First published: Tue Oct 16 2007(Updated: )
Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod 0.48 Half-Life Dedicated Server plugin allows remote attackers to inject arbitrary web script or HTML via the redir parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Valve Software Half-life Dedicated Server | ||
Valve Software Webmod Plugin | =0.48 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5477 has a moderate severity level due to its potential to allow cross-site scripting (XSS) attacks.
To fix CVE-2007-5477, you should validate and sanitize the input for the redir parameter in the affected plugin.
CVE-2007-5477 affects the Valve Software Half-Life Dedicated Server and the WebMod Plugin version 0.48.
Exploiting CVE-2007-5477 can allow attackers to inject arbitrary web scripts or HTML, leading to potential session hijacking or phishing.
Yes, upgrading the WebMod Plugin to a newer version may resolve the vulnerabilities associated with CVE-2007-5477.