Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-0939 | First vendor Publication | 2007-04-10 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0939 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:1575 | |||
Oval ID: | oval:org.mitre.oval:def:1575 | ||
Title: | CMS Cross-Site Scripting and Spoofing Vulnerability | ||
Description: | Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2007-0939 | Version: | 8 |
Platform(s): | Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows XP Microsoft Windows 2000 | Product(s): | Microsoft Content Management Server 2001 Microsoft Content Management Server 2002 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
34007 | Microsoft Content Management Server (CMS) Unspecified XSS Microsoft Content Management Server (2001/2002) contains a flaw that allows a remote cross site scripting attack. This flaw exists because unspecified input is not properly sanitized before being returned to users. This vulnerability can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site, leading to a loss of integrity and confidentially |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2007-04-12 | IAVM : 2007-B-0007 - Multiple Vulnerabilities in Microsoft Content Management Server Severity : Category I - VMSKEY : V0013935 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Content Management Server memory corruption RuleID : 11191 - Revision : 13 - Type : SERVER-IIS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-04-11 | Name : A remote user can execute arbitrary code on the remote host. File : smb_nt_ms07-018.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:17:45 |
|
2024-11-28 12:11:33 |
|
2021-05-04 12:05:23 |
|
2021-04-22 01:05:56 |
|
2020-05-23 00:19:17 |
|
2018-10-16 21:19:49 |
|
2018-10-13 00:22:36 |
|
2017-10-11 09:23:51 |
|
2016-06-28 16:12:15 |
|
2016-04-26 15:46:20 |
|
2014-02-17 10:39:08 |
|
2013-11-11 12:37:40 |
|
2013-05-11 10:19:22 |
|