CVE-2007-2976: XSS
Centrinity FirstClass 8.3 and earlier, and Server and Internet Services 8.0 and earlier, do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS) attacks. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2976?
The severity of CVE-2007-2976 is medium with a score of 4.3.
What type of vulnerability is CVE-2007-2976?
CVE-2007-2976 is a cross-site scripting (XSS) vulnerability.
How does CVE-2007-2976 allow exploitation?
CVE-2007-2976 allows exploitation through improper handling of a URL containing a null character, enabling remote attackers to conduct XSS attacks.
Which software is affected by CVE-2007-2976?
CVE-2007-2976 affects Centrinity FirstClass 8.3 and earlier, as well as Server and Internet Services 8.0 and earlier.
How can I mitigate the risks associated with CVE-2007-2976?
To mitigate the risks of CVE-2007-2976, it is recommended to upgrade to the latest version of the affected software.