CVE-2007-3120: XSS
Cross-site scripting (XSS) vulnerability in public/code/cpdpage.php in All In One Control Panel (AIOCP) before 1.3.017 allows remote attackers to inject arbitrary web script or HTML via the aiocpdp parameter. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which deployments are affected?
AIOCP versions before 1.3.017 are affected. The issue is in public/code/cp_dpage.php and involves the aiocp_dp parameter.
What does an attacker need to exploit this issue?
The vulnerability can be exploited remotely without authentication. Exploitation requires supplying malicious script or HTML through the aiocp_dp parameter, with attack complexity rated medium.
Is confidentiality or availability directly affected?
The provided impact vector identifies integrity impact as partial, with no direct confidentiality or availability impact.
What should be done to remediate it?
Apply the available patch by updating to AIOCP 1.3.017 or later.