CVE-2007-6309: XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the galleryID parameter in a usergallery upload action; or the (2) upID, (3) tag, (4) month, (5) userID, or (6) year parameter in a calendar announce action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6309?
The severity of CVE-2007-6309 is considered medium due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2007-6309?
To fix CVE-2007-6309, update webSPELL to the latest version that addresses these XSS vulnerabilities.
What versions are affected by CVE-2007-6309?
CVE-2007-6309 specifically affects webSPELL version 4.1.2.
What type of vulnerability is CVE-2007-6309?
CVE-2007-6309 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts.
Can CVE-2007-6309 be exploited remotely?
Yes, CVE-2007-6309 can be exploited remotely by attackers through specific parameters in web requests.