Lucene search

K
cve[email protected]CVE-2007-3818
HistoryJul 17, 2007 - 1:30 a.m.

CVE-2007-3818

2007-07-1701:30:00
web.nvd.nist.gov
25
cve-2007-3818
cross-site scripting
xss
logintoboggan
drupal
security vulnerability

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.2%

Cross-site scripting (XSS) vulnerability in the LoginToboggan module 5.x-1.x-dev before 20070712 for Drupal allows remote authenticated users with “administer blocks” permission to inject arbitrary JavaScript and gain privileges via “the message displayed above the default user login block.”

Affected configurations

NVD
Node
drupallogintoboggan_moduleRange4.7.x-1.0
OR
drupallogintoboggan_moduleRange5.x-1.x-dev

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

5.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.2%

Related for CVE-2007-3818