First published: Wed Feb 28 2007(Updated: )
WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Post icon field, (4) the Edit Profile, and (5) the Gallery, which has unknown impact and remote attack vectors, possibly related to cross-site scripting (XSS).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WebAPP | =0.9.9 | |
WebAPP | =0.9.9.1 | |
WebAPP | =0.9.9.2 | |
WebAPP | =0.9.9.2.1 | |
WebAPP | =0.9.9.3 | |
WebAPP | =0.9.9.3.1 | |
WebAPP | =0.9.9.3.2 | |
WebAPP | =0.9.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-1177 is currently classified as unknown, but it is associated with potential cross-site scripting (XSS) vulnerabilities.
To mitigate CVE-2007-1177, update to WebAPP version 0.9.9.5 or later, which includes proper character filtering.
CVE-2007-1177 affects multiple versions of WebAPP, specifically all versions prior to 0.9.9.5.
CVE-2007-1177 impacts contexts related to the query string, profiles, forum post icon fields, edit profile, and gallery.
Yes, CVE-2007-1177 has been identified as having unknown remote attack vectors that could be exploited.