CVE Database
/

CVE-2007-4523

Back to search

CVE-2007-4523

Published: Aug 25, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php, probably involving the Title or textarea field as reachable through admin/pages/new_page.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS.

VendorProductVersions

n/a

n/a

affected
n/a

References

38444
vdb-entry
x_refsource_OSVDB
38448
vdb-entry
x_refsource_OSVDB
38446
vdb-entry
x_refsource_OSVDB
ripe-multiple-xss(36179)
vdb-entry
x_refsource_XF
25406
vdb-entry
x_refsource_BID
3058
third-party-advisory
x_refsource_SREASON
38449
vdb-entry
x_refsource_OSVDB
38447
vdb-entry
x_refsource_OSVDB
38445
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now