CVE Database
/

CVE-2007-3060

Back to search

CVE-2007-3060

Published: Jun 6, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to (a) chat.php, (2) LANG[DEFAULT_BRANDING] and (3) PHPLIVE_VERSION parameters to (b) help.php, the (4) admin[name] parameter to (c) admin/header.php, and the (5) BASE_URL parameter to (d) super/info.php, and in some cases, the LANG[DEFAULT_BRANDING], PHPLIVE_VERSION, and (6) nav_line parameters to setup/footer.php, different vectors than CVE-2006-6769.

VendorProductVersions

n/a

n/a

affected
n/a

References

36986
vdb-entry
x_refsource_OSVDB
36989
vdb-entry
x_refsource_OSVDB
36987
vdb-entry
x_refsource_OSVDB
38383
vdb-entry
x_refsource_OSVDB
ADV-2007-2082
vdb-entry
x_refsource_VUPEN
36988
vdb-entry
x_refsource_OSVDB
20070601 PHPLive ALL VERSION: RFI + XSS
mailing-list
x_refsource_FULLDISC
20070601 bugtraq submission
mailing-list
x_refsource_BUGTRAQ
38381
vdb-entry
x_refsource_OSVDB
24276
vdb-entry
x_refsource_BID
38379
vdb-entry
x_refsource_OSVDB
38382
vdb-entry
x_refsource_OSVDB
25441
third-party-advisory
x_refsource_SECUNIA
36990
vdb-entry
x_refsource_OSVDB
38380
vdb-entry
x_refsource_OSVDB
20070604 RE: bugtraq submission
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now