First published: Fri Jun 08 2007(Updated: )
Cross-site scripting (XSS) vulnerability in atomPhotoBlog.php in Atom Photoblog 1.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tag parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apertoblog | <=1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3135 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2007-3135, you should upgrade to a version of Atom Photoblog newer than 1.0.9 or implement input validation and sanitization on the tag parameter.
Users of Atom Photoblog version 1.0.9 and earlier are affected by CVE-2007-3135.
CVE-2007-3135 is a cross-site scripting (XSS) vulnerability that allows remote code injection via a web browser.
An attacker exploiting CVE-2007-3135 can inject arbitrary web scripts or HTML into the affected application, potentially compromising user data and sessions.