First published: Tue Jul 03 2007(Updated: )
Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenable Nessus | <=3.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3546 is classified as a high severity vulnerability due to its potential to allow remote attackers to inject malicious scripts.
To fix CVE-2007-3546, update the Nessus Vulnerability Scanner to version 3.0.6 or later.
CVE-2007-3546 can facilitate cross-site scripting (XSS) attacks that could compromise user sessions or redirect users to malicious websites.
CVE-2007-3546 affects Nessus versions prior to 3.0.6, specifically up to and including version 3.0.5.
Yes, CVE-2007-3546 allows attackers to inject arbitrary web scripts or HTML via unspecified vectors, making user input a potential attack vector.