CVE Database
/

CVE-2007-1576

Back to search

CVE-2007-1576

Published: Mar 21, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Search (only Gecko engine driven Browsers), and (5) Notes modules; the (6) Mail summary page; and unspecified other files.

VendorProductVersions

n/a

n/a

affected
n/a

References

34064
vdb-entry
x_refsource_OSVDB
34068
vdb-entry
x_refsource_OSVDB
34065
vdb-entry
x_refsource_OSVDB
34066
vdb-entry
x_refsource_OSVDB
34067
vdb-entry
x_refsource_OSVDB
34069
vdb-entry
x_refsource_OSVDB
24509
third-party-advisory
x_refsource_SECUNIA
22957
vdb-entry
x_refsource_BID
GLSA-200706-07
vendor-advisory
x_refsource_GENTOO
2459
third-party-advisory
x_refsource_SREASON
25748
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now