First published: Tue Apr 03 2007(Updated: )
Cross-site scripting (XSS) vulnerability in the show_recent_searches function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to inject arbitrary web script or HTML via the srch variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Web App.net Webapp |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7187 is considered a medium-severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-7187, you should update to the latest version of web-app.net WebAPP released after September 9, 2006.
CVE-2006-7187 is caused by improper validation of the srch variable in the show_recent_searches function.
Any user running web-app.net WebAPP versions before September 9, 2006, is affected by CVE-2006-7187.
CVE-2006-7187 can be exploited to execute arbitrary web scripts or HTML via crafted requests to the vulnerable application.