Lucene search

K
cveMitreCVE-2015-7708
HistoryOct 05, 2015 - 3:59 p.m.

CVE-2015-7708

2015-10-0515:59:05
CWE-79
mitre
web.nvd.nist.gov
31
cve-2015-7708
cross-site scripting
xss
4images
nvd
security vulnerability
web security
remote attack

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.002

Percentile

60.9%

Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat_description parameter in an updatecat action to admin/categories.php.

Affected configurations

Nvd
Node
4homepages4imagesRange1.7.11
VendorProductVersionCPE
4homepages4images*cpe:2.3:a:4homepages:4images:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.002

Percentile

60.9%

Related for CVE-2015-7708