First published: Thu Oct 11 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inject arbitrary web script or HTML via the (1) group or (2) utag parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWin DNewsWeb | =57e1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-5370 is considered moderate due to its potential for cross-site scripting attacks.
To fix CVE-2007-5370, it is recommended to update to a patched version of NetWin DNewsWeb or implement input validation to sanitize the group and utag parameters.
CVE-2007-5370 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
CVE-2007-5370 affects NetWin DNewsWeb version 57e1.
Yes, CVE-2007-5370 can affect user sessions by executing malicious scripts in the context of the user's browser.