CVE-2007-2625: XSS
Published May 11, 2007
·Updated
Cross-site scripting (XSS) vulnerability in shared/code/cpauthorization.php in All In One Control Panel (AIOCP) before 1.3.016 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: some of these details are obtained from third party information.
Affected Software
1 affected component
AIOCP AIOCP<=1.3.015
Remediation
Event History
May 11, 2007
CVE Published
05:19 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
Which deployments are affected?
AIOCP versions before 1.3.016 are affected. The vulnerability is in shared/code/cp_authorization.php.
2
What does an attacker need to exploit this issue?
The issue can be exploited remotely without authentication, according to the supplied attack vector. The affected input parameters are unspecified in the available information.
3
What should teams do to remediate it?
Apply the available patch or update to AIOCP 1.3.016 or later. The provided information does not identify a workaround for systems that cannot be patched immediately.