4.3
CVE-2007-3131
- EPSS 1.13%
- Veröffentlicht 08.06.2007 16:30:00
- Zuletzt bearbeitet 16.06.2026 22:41:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in add_comment.php in Light Blog 4.1 before 20070606 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Public Warehouse ≫ Light Blog Version4.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.13% | 0.622 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/25561
http://securityreason.com/securityalert/2783
http://www.securityfocus.com/archive/1/470673/100/0/threaded
http://www.secvsn.com/content/Advisories/sr-060607-lightblog.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/34753