First published: Thu Jul 19 2007(Updated: )
Cross-site scripting (XSS) vulnerability in Bandersnatch 0.4 allows remote attackers to inject arbitrary JavaScript via a Jabber resource name and possibly other data items, which are stored in conversation logs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jason Alexander phNNTP | =0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3910 is considered a medium severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
To fix CVE-2007-3910, you should upgrade to a version of Bandersnatch that is not affected by this vulnerability.
CVE-2007-3910 is caused by improper handling of user input in Bandersnatch, allowing for the injection of arbitrary JavaScript.
CVE-2007-3910 affects users of Bandersnatch version 0.4.
CVE-2007-3910 can enable remote attackers to execute arbitrary JavaScript in the context of a user's session.