CVE-2007-4874: XSS
Published Sep 26, 2007
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) lusername parameter to admin/layout2b.php, and the (2) backurl parameter to comment.php.
Affected Software
1 affected component
Boesch-it Simpnews=2.41.03
Event History
Sep 26, 2007
CVE Published
08:17 PM
Sep 27, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4874?
CVE-2007-4874 is categorized as a moderate severity vulnerability due to the risk of cross-site scripting attacks.
2
How do I fix CVE-2007-4874?
To fix CVE-2007-4874, update to a patched version of SimpNews that addresses the XSS vulnerabilities.
3
Which parameters are affected by CVE-2007-4874?
CVE-2007-4874 affects the l_username parameter in admin/layout2b.php and the backurl parameter in comment.php.
4
What type of vulnerability is CVE-2007-4874?
CVE-2007-4874 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject web scripts.
5
What versions of SimpNews are impacted by CVE-2007-4874?
SimpNews version 2.41.03 is impacted by CVE-2007-4874.