Vulnerability Name: | CVE-2007-5702 (CCN-37399) | ||||||||
Assigned: | 2007-10-23 | ||||||||
Published: | 2007-10-23 | ||||||||
Updated: | 2018-10-15 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows remote attackers to inject arbitrary web script or HTML via the username parameter. Note: some of these details are obtained from third party information. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Tue Oct 23 2007 - 19:02:01 CDT Novell OpenSUSE SWAMP multiple XSS Source: MITRE Type: CNA CVE-2007-5702 Source: CCN Type: SWAMP Web site SWAMP - Workflow Administration and Management Platform Source: CCN Type: SA27390 SWAMP "username" Cross-Site Scripting Vulnerability Source: SECUNIA Type: Vendor Advisory 27390 Source: CONFIRM Type: UNKNOWN http://swamp.svn.sourceforge.net/viewvc/swamp/trunk/swamp/webapps/webswamp/src/java/de/suse/swamp/modules/actions/LoginActions.java?r1=666&r2=700 Source: OSVDB Type: UNKNOWN 38203 Source: CCN Type: OSVDB ID: 38203 SWAMP swamp/action/LoginActions username Parameter XSS Source: BUGTRAQ Type: UNKNOWN 20071024 Novell OpenSUSE SWAMP multiple XSS Source: BID Type: UNKNOWN 26198 Source: CCN Type: BID-26198 SWAMP Login Pages Cross-Site Scripting Vulnerability Source: XF Type: UNKNOWN novell-swamp-login-xss(37399) Source: XF Type: UNKNOWN novell-swamp-login-xss(37399) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |