Lucene search

K
nvd[email protected]NVD:CVE-2007-5492
HistoryOct 17, 2007 - 7:17 p.m.

CVE-2007-5492

2007-10-1719:17:00
CWE-94
web.nvd.nist.gov
6

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.005

Percentile

77.3%

Static code injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP code via the value parameter.

Affected configurations

Nvd
Node
sitebarsitebarMatch3.3.8
VendorProductVersionCPE
sitebarsitebar3.3.8cpe:2.3:a:sitebar:sitebar:3.3.8:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.005

Percentile

77.3%