CVE-2007-4365: XSS
Published Aug 15, 2007
·Updated
Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a setlang cookie to an unspecified component. NOTE: this may overlap CVE-2007-1965.
Affected Software
1 affected component
eXV2 Content Management System<=2.0.5
Event History
Aug 15, 2007
CVE Published
07:17 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4365?
The severity of CVE-2007-4365 is considered to be moderate due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2007-4365?
To fix CVE-2007-4365, upgrade to a version of eXV2 CMS later than 2.0.5 that addresses this vulnerability.
3
Who is affected by CVE-2007-4365?
CVE-2007-4365 affects users of eXV2 CMS version 2.0.5 and earlier.
4
What type of vulnerability is CVE-2007-4365?
CVE-2007-4365 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2007-4365?
Attackers can inject arbitrary web scripts or HTML via a manipulated set_lang cookie in CVE-2007-4365.