First published: Tue Apr 03 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to inject arbitrary web script or HTML via (1) the QUERY_STRING corresponding to drop downs or (2) various forms.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WebAPP | =0.9.9.1 | |
WebAPP | =0.9.9.2 | |
WebAPP | =0.9.9.2.1 | |
WebAPP | =0.9.9.2.2 | |
WebAPP | =0.9.9.3 | |
WebAPP | =0.9.9.3.1 | |
WebAPP | =0.9.9.3.2 | |
WebAPP | =0.9.9.3.3 | |
WebAPP | =0.9.9.3.4 | |
WebAPP | =0.9.9.3.5 | |
WebAPP | =0.9.9.4 | |
WebAPP | =0.9.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1828 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2007-1828, upgrade to WebAPP version 0.9.9.6 or later, which addresses the identified XSS vulnerabilities.
CVE-2007-1828 allows authenticated remote users to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
CVE-2007-1828 affects WebAPP versions prior to 0.9.9.6, including versions 0.9.9.3.4, 0.9.9.3.5, 0.9.9.3.3, and others.
Yes, exploitation of CVE-2007-1828 requires the attacker to be an authenticated user of the WebAPP.