CVE-2007-3501: XSS
Published Jun 30, 2007
·Updated
Cross-site scripting (XSS) vulnerability in CMDUSERSTATS in DirectAdmin 1.30.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vector than CVE-2007-1508.
Affected Software
1 affected component
DirectAdmin DirectAdmin<=1.30.1
Event History
Jun 30, 2007
CVE Published
01:30 AM
Data Sourced
via NVD·01:30 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3501?
CVE-2007-3501 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2007-3501?
To fix CVE-2007-3501, upgrade DirectAdmin to version 1.30.2 or later to eliminate the vulnerability.
3
What type of vulnerability is CVE-2007-3501?
CVE-2007-3501 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary scripts.
4
Which versions of DirectAdmin are affected by CVE-2007-3501?
CVE-2007-3501 affects DirectAdmin version 1.30.1 and earlier.
5
What is the attack vector for CVE-2007-3501?
The attack vector for CVE-2007-3501 involves the domain parameter in the CMD_USER_STATS functionality.