CVE-2007-4900: XSS
Published Sep 14, 2007
·Updated
Cross-site scripting (XSS) vulnerability in the logon page in RSA EnVision 3.3.6 Build 0115 allows remote attackers to inject arbitrary web script or HTML via the username field.
Affected Software
1 affected component
RSA EnVision=3.3.6_build_0115
Event History
Sep 14, 2007
CVE Published
06:17 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4900?
CVE-2007-4900 has a medium severity rating due to its ability to allow cross-site scripting attacks.
2
How do I fix CVE-2007-4900?
To fix CVE-2007-4900, upgrade to a patched version of RSA EnVision that addresses the XSS vulnerability.
3
What type of vulnerability is CVE-2007-4900?
CVE-2007-4900 is classified as a cross-site scripting (XSS) vulnerability.
4
Which software versions are affected by CVE-2007-4900?
CVE-2007-4900 affects RSA EnVision version 3.3.6 Build 0115.
5
What can attackers do with CVE-2007-4900?
Attackers can inject arbitrary web scripts or HTML through the username field in the logon page.