CVE-2007-3008: XSS
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3008?
The severity of CVE-2007-3008 is not explicitly rated but it poses risks related to remote information leaks and cross-site tracing attacks.
How do I fix CVE-2007-3008?
To fix CVE-2007-3008, you should upgrade to Mbedthis AppWeb version 2.2.2 or later, which disables the HTTP TRACE method.
Which versions of Mbedthis AppWeb are affected by CVE-2007-3008?
Versions 2.0.0 to 2.2.1 of Mbedthis AppWeb HTTP server are affected by CVE-2007-3008.
What are the potential impacts of CVE-2007-3008?
CVE-2007-3008 can enable remote information leaks and make systems vulnerable to cross-site tracing (XST) attacks.
Is CVE-2007-3008 related to any other vulnerabilities?
Yes, CVE-2007-3008 is related to CVE-2004-2320 and CVE-2005-3398 regarding similar risks associated with HTTP methods.