First published: Mon Oct 29 2007(Updated: )
Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell OpenSUSE SWAMP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5702 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2007-5702, sanitize the input in the username parameter to prevent script injection.
CVE-2007-5702 affects Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x.
Remote attackers can exploit CVE-2007-5702 to inject arbitrary web scripts or HTML via the username parameter.
CVE-2007-5702 enables cross-site scripting (XSS) attacks on vulnerable systems.