CVE-2007-0660: XSS
Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "Pass through values."
Other sources
Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN), caused by improper validation of user-supplied input by an unspecified script. Pass through values were not getting filtered, leaving them vulnerable to XSS. A remote attacker could exploit this vulnerability using various parameters in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0660?
CVE-2007-0660 is classified as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2007-0660?
To fix CVE-2007-0660, upgrade the IFrame module to version 03.02.01 or later.
What software is affected by CVE-2007-0660?
CVE-2007-0660 affects DotNetNuke IFrame module versions prior to 03.02.01.
What kind of attack can CVE-2007-0660 enable?
CVE-2007-0660 can enable remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts.
Where can I find more information about CVE-2007-0660?
For more information about CVE-2007-0660, consult security advisories and vulnerability databases that track this issue.