| Vulnerability Name: | CVE-2007-2739 (CCN-34323) | ||||||||||||||||
| Assigned: | 2007-05-16 | ||||||||||||||||
| Published: | 2007-05-16 | ||||||||||||||||
| Updated: | 2017-07-29 | ||||||||||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in xajax before 0.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||||||||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2007-2739 Source: OSVDB Type: UNKNOWN 36174 Source: CCN Type: SA25299 xajax Unspecified Cross-Site Scripting Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 25299 Source: SECUNIA Type: UNKNOWN 33265 Source: CCN Type: SourceForge.net: Files xajax PHP and Javascript library - File Release Notes and Changelog - Release Name: version 0.2.5 Source: CONFIRM Type: UNKNOWN http://sourceforge.net/project/shownotes.php?release_id=508650 Source: DEBIAN Type: UNKNOWN DSA-1692 Source: DEBIAN Type: DSA-1692 php-xajax -- insufficient input sanitising Source: CCN Type: OSVDB ID: 36174 xajax Unspecified XSS Source: CCN Type: BID-24006 Xajax Unspecified Cross-Site Scripting Vulnerability Source: VUPEN Type: UNKNOWN ADV-2007-1841 Source: XF Type: UNKNOWN xajax-xajaxinc-xss(34323) Source: XF Type: UNKNOWN xajax-xajaxinc-xss(34323) | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||