4.3
CVE-2007-4264
- EPSS 1.5%
- Veröffentlicht 09.08.2007 10:17:00
- Zuletzt bearbeitet 16.06.2026 22:43:42
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) 1.5.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) path and (2) download parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kai Blankenhorn Bitfolge ≫ Simple And Nice Index File Version <= 1.5.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.5% | 0.708 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://osvdb.org/38701
http://pridels-team.blogspot.com/2007/08/snif-xss-vuln.html
http://www.securityfocus.com/bid/25212
https://exchange.xforce.ibmcloud.com/vulnerabilities/35813