CVE-2007-6489: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gbmail, (2) gbname, and (3) gbtext parameters in a guestbook action to index.php, and unspecified other vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6489?
CVE-2007-6489 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2007-6489?
To fix CVE-2007-6489, update to a secure version of Falcon Series One CMS that addresses these cross-site scripting issues.
What are the affected parameters in CVE-2007-6489?
The affected parameters in CVE-2007-6489 are gb_mail, gb_name, and gb_text in the guestbook action of index.php.
Can CVE-2007-6489 be exploited remotely?
Yes, CVE-2007-6489 can be exploited remotely by attackers to inject malicious scripts into the application.
Which version of Falcon Series One CMS is impacted by CVE-2007-6489?
The impacted version by CVE-2007-6489 is Falcon Series One CMS 1.4.3.