CVE-2007-1965: XSS
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the setlang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1965?
The severity of CVE-2007-1965 is considered medium due to the potential for cross-site scripting attacks.
How do I fix CVE-2007-1965?
To fix CVE-2007-1965, upgrade to a version of eXV2 CMS later than 2.0.4.3 that addresses the XSS vulnerabilities.
What systems are affected by CVE-2007-1965?
CVE-2007-1965 affects eXV2 CMS versions 2.0.4.3 and earlier, allowing for XSS vulnerabilities through specific parameters.
What are the attack vectors for CVE-2007-1965?
Attackers can exploit CVE-2007-1965 by injecting arbitrary scripts via the set_lang parameter in archive.php, article.php, index.php, or topics.php.
Can CVE-2007-1965 be exploited remotely?
Yes, CVE-2007-1965 can be exploited remotely by an attacker through crafted HTTP requests.