First published: Tue May 22 2007(Updated: )
Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in a sendpwd task.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbox CMS | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2686 is considered a medium-severity vulnerability due to its potential for exploitation through cross-site scripting.
To mitigate CVE-2007-2686, it is recommended to sanitize and validate user input in the login parameter to prevent script injection.
CVE-2007-2686 affects Jetbox CMS version 2.1.
CVE-2007-2686 enables remote attackers to execute arbitrary web scripts or HTML through cross-site scripting.
While CVE-2007-2686 is an older vulnerability, it remains relevant for systems still using Jetbox CMS version 2.1.