CVE Database
/

CVE-2007-0364

Back to search

CVE-2007-0364

Published: Jan 19, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b) user_detail.php; the (3) friend_name, (4) friend_email, (5) error_msg, (6) my_name, (7) my_email, and (8) id parameters to (c) tell_friend.php; the (9) error_msg, (10) email, (11) name, and (12) subject parameters to (d) sendmail.php; the (13) email, (14) error_msg, and (15) username parameters to (e) send_pwd.php; the (16) keyword parameter to (f) search.php; the (17) error_msg, (18) username, (19) password, (20) password2, and (21) email parameters to (g) register.php; the (22) url, (23) contact_name, and (24) email parameters to (h) power_search.php; the (25) path and (26) total parameters to (i) new.php; the (27) query parameter to (j) modify.php; the (28) error_msg parameter to (k) login.php; the (29) error_msg and (30) email parameters to (l) mailing_list.php; the (31) gateway parameter to (m) upgrade.php; and another unspecified vector.

VendorProductVersions

n/a

n/a

affected
n/a

References

32846
vdb-entry
x_refsource_OSVDB
ADV-2007-0222
vdb-entry
x_refsource_VUPEN
32849
vdb-entry
x_refsource_OSVDB
32840
vdb-entry
x_refsource_OSVDB
32850
vdb-entry
x_refsource_OSVDB
32843
vdb-entry
x_refsource_OSVDB
32845
vdb-entry
x_refsource_OSVDB
32842
vdb-entry
x_refsource_OSVDB
22084
vdb-entry
x_refsource_BID
32847
vdb-entry
x_refsource_OSVDB
32848
vdb-entry
x_refsource_OSVDB
32844
vdb-entry
x_refsource_OSVDB
32839
vdb-entry
x_refsource_OSVDB
indexu-multiple-scripts-xss(31538)
vdb-entry
x_refsource_XF
32838
vdb-entry
x_refsource_OSVDB
32851
vdb-entry
x_refsource_OSVDB
23764
third-party-advisory
x_refsource_SECUNIA
32841
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now