CVE-2007-4959: XSS
Cross-site scripting (XSS) vulnerability in catalogproductswithimages.php in osCMax 2.0.0-RC3-0-1 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4959?
CVE-2007-4959 is considered a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2007-4959?
To fix CVE-2007-4959, you should sanitize user input in the catalog_products_with_images.php file to prevent script injection.
Which software versions are affected by CVE-2007-4959?
CVE-2007-4959 affects osCMax version 2.0.0-RC3-0-1.
What is the impact of exploiting CVE-2007-4959?
Exploiting CVE-2007-4959 allows remote attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or site defacement.
Is there a patch available for CVE-2007-4959?
There is no specific patch for CVE-2007-4959; the application must be manually updated to address the XSS vulnerability.