CVE-2007-0175: XSS
Published Jan 11, 2007
·Updated
Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirectto parameter.
Affected Software
3 affected components
b2evolution b2evolution=1.8.5
b2evolution b2evolution=1.8.2
b2evolution b2evolution=1.8.6
Event History
Jan 11, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0175?
CVE-2007-0175 is considered a medium-severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2007-0175?
To fix CVE-2007-0175, upgrade b2evolution to a later version than 1.8.6 that implements proper input validation.
3
Which versions are affected by CVE-2007-0175?
CVE-2007-0175 affects b2evolution versions 1.8.2, 1.8.5, and 1.8.6.
4
What type of vulnerability is CVE-2007-0175?
CVE-2007-0175 is a cross-site scripting (XSS) vulnerability.
5
Can remote attackers exploit CVE-2007-0175?
Yes, CVE-2007-0175 allows remote attackers to inject arbitrary web scripts or HTML.