First published: Thu Nov 15 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) func or (2) date parameter, or the jid parameter in a (3) log or (4) user action, a different vulnerability than CVE-2007-3910.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jason Alexander phNNTP | =0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6001 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2007-6001, it is recommended to upgrade Bandersnatch to a version that addresses the identified XSS vulnerabilities.
CVE-2007-6001 specifically affects index.php in Bandersnatch version 0.4.
CVE-2007-6001 can be exploited for cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Users of Bandersnatch version 0.4 are impacted by CVE-2007-6001 and are at risk if they do not apply the necessary patches or updates.