CVE-2007-2732: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter to view/search/; or the (2) companyname, (3) country, (4) email, (5) firstname, (6) middlename, (7) required, (8) surname, or (9) title parameter to view/supplynews/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2732?
CVE-2007-2732 is classified as a high-severity vulnerability due to its potential to allow remote attackers to execute arbitrary scripts.
How do I fix CVE-2007-2732?
To mitigate CVE-2007-2732, ensure that user input is properly sanitized and validated to prevent JavaScript injection.
Which versions of Jetbox CMS are affected by CVE-2007-2732?
CVE-2007-2732 affects Jetbox CMS version 2.1.
What types of attacks are possible with CVE-2007-2732?
CVE-2007-2732 can be exploited for cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Are there known exploits for CVE-2007-2732?
Yes, there are known exploits for CVE-2007-2732 that leverage the vulnerabilities in the parameters mentioned to perform XSS attacks.