4.3
CVE-2007-3189
- EPSS 3.97%
- Veröffentlicht 12.06.2007 23:30:00
- Zuletzt bearbeitet 16.06.2026 22:41:14
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jffnms ≫ Just For Fun Network Management System Version0.8.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.97% | 0.891 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://marc.info/?l=full-disclosure&m=118151087109711&w=2
http://secunia.com/advisories/25587
http://secunia.com/advisories/26769
http://www.debian.org/security/2007/dsa-1374
http://www.securityfocus.com/archive/1/471039/100/0/threaded
http://www.securityfocus.com/bid/24414