CVE-2007-5190: XSS
Published Oct 22, 2007
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the action parameter to php-bin/Webclient.php or (2) the Langue parameter to the default URI.
Affected Software
1 affected component
Alcatel-Lucent OmniVista<=4760_r4.2
Remediation
Patch Available
Patch Available
Event History
Oct 22, 2007
CVE Published
07:46 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5190?
CVE-2007-5190 is considered to have a medium severity due to its ability to facilitate cross-site scripting attacks.
2
How do I fix CVE-2007-5190?
To fix CVE-2007-5190, upgrade to a newer version of Alcatel OmniVista that addresses the XSS vulnerabilities.
3
What software is affected by CVE-2007-5190?
CVE-2007-5190 affects Alcatel OmniVista versions R4.2 and earlier.
4
What type of vulnerability is CVE-2007-5190?
CVE-2007-5190 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2007-5190 be exploited remotely?
Yes, CVE-2007-5190 allows remote attackers to exploit the vulnerability through crafted web requests.