CVE-2007-3918: XSS
Published Oct 5, 2007
·Updated
Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirmhash parameter.
Affected Software
1 affected component
GForge=4.6_b2
Event History
Oct 5, 2007
CVE Published
10:17 PM
Oct 6, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3918?
CVE-2007-3918 has been classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2007-3918?
To fix CVE-2007-3918, upgrade to a patched version of GForge that addresses this XSS issue.
3
What types of attacks can CVE-2007-3918 facilitate?
CVE-2007-3918 can facilitate remote attackers in injecting arbitrary web scripts or HTML, potentially leading to session hijacking.
4
Which versions of GForge are affected by CVE-2007-3918?
CVE-2007-3918 specifically affects GForge version 4.6b2.
5
What is the confirm_hash parameter in CVE-2007-3918?
In the context of CVE-2007-3918, the confirm_hash parameter is the input vector that allows injection of malicious scripts.