Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2007-5692 | First vendor Publication | 2007-10-29 |
| Vendor | Cve | Last vendor Modification | 2011-03-07 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
|---|---|---|---|
| Cvss Base Score | 4.3 | Attack Range | Network |
| Cvss Impact Score | 2.9 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Multiple cross-site scripting (XSS) vulnerabilities in SiteBar 3.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to integrator.php; (2) the token parameter in a New Password action, (3) the nid_acl parameter in a Folder Properties action, or (4) the uid parameter in a Modify User action to command.php; or (5) the target parameter to index.php, different vectors than CVE-2006-3320. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5692 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 1 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 41359 | SiteBar index.php target Parameter XSS |
| 41358 | SiteBar command.php Modify User Action uid Parameter XSS |
| 41357 | SiteBar Folder Properties Action nid_acl Parameter XSS |
| 41356 | SiteBar New Password Action token Parameter XSS |
| 41355 | SiteBar integrator.php lang Parameter XSS |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-05-11 10:40:41 |
|

CVE-2007-5692
(Critical)





