CVE-2007-3839 - CERT CVE
ID CVE-2007-3839
Sažetak Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 010306 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Reference
CVSS
Base: 4.0
Impact: 4.9
Exploitability:4.9
Pristup
VektorSloženostAutentikacija
NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:N/AC:H/Au:N/C:P/I:P/A:N
Zadnje važnije ažuriranje 05-09-2008 - 21:26
Objavljeno 17-07-2007 - 22:30