Lucene search

K
cve[email protected]CVE-2007-1177
HistoryMar 02, 2007 - 9:18 p.m.

CVE-2007-1177

2007-03-0221:18:00
web.nvd.nist.gov
27
webapp
security
vulnerability
filtering
xss
nvd
cve-2007-1177

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.2 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.9%

WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Post icon field, (4) the Edit Profile, and (5) the Gallery, which has unknown impact and remote attack vectors, possibly related to cross-site scripting (XSS).

Affected configurations

NVD
Node
web-app.orgwebappMatch0.9.9
OR
web-app.orgwebappMatch0.9.9.1
OR
web-app.orgwebappMatch0.9.9.2
OR
web-app.orgwebappMatch0.9.9.2.1
OR
web-app.orgwebappMatch0.9.9.3
OR
web-app.orgwebappMatch0.9.9.3.1
OR
web-app.orgwebappMatch0.9.9.3.2
OR
web-app.orgwebappMatch0.9.9.4

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.2 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.9%

Related for CVE-2007-1177