Vulnerability Name: | CVE-2007-5888 (CCN-38290) | ||||||||
Assigned: | 2007-11-05 | ||||||||
Published: | 2007-11-05 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in displayecard.php in Coppermine Photo Gallery (CPG) before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the data parameter. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Coppermine Photo Gallery Web site Coppermine Photo Gallery Source: CCN Type: Coppermine Gallery Forum, November 5, 2007 09:05:36 AM Maintenance release cpg1.4.14 (security-related) - upgrade mandatory Source: CONFIRM Type: Patch http://coppermine-gallery.net/forum/index.php?topic=48106.0 Source: MITRE Type: CNA CVE-2007-5888 Source: OSVDB Type: UNKNOWN 38420 Source: CCN Type: SA27534 Coppermine Photo Gallery "data" Cross-Site Scripting Source: SECUNIA Type: Patch, Vendor Advisory 27534 Source: CCN Type: OSVDB ID: 38420 Coppermine Photo Gallery displayecard.php data Parameter XSS Source: BID Type: UNKNOWN 26357 Source: CCN Type: BID-26357 Coppermine Photo Gallery Displayecard.PHP Cross-Site Scripting Vulnerability Source: XF Type: UNKNOWN coppermine-displayecard-xss(38290) Source: XF Type: UNKNOWN coppermine-displayecard-xss(38290) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |