CVE Database
/

CVE-2007-4588

Back to search

CVE-2007-4588

Published: Aug 29, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Server Admin Level (NodeWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php; and allow remote authenticated users to inject arbitrary web script or HTML via the PATH_INFO to (2) nodeworx.php, (3) users.php, (4) lang.php, (5) themes.php, (6) setup.php, (7) siteworx.php, (8) packages.php, (9) backup.php, (10) import.php, (11) scriptworx.php, (12) resellers.php, (13) reseller-packages.php, (14) http.php, (15) mail.php, (16) ftp.php, (17) mysql.php, (18) sshd.php, (19) nfs.php, (20) cron.php, (21) ip.php, (22) firewall.php, (23) updates.php, (24) rrd.php, or (25) cluster.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

36762
vdb-entry
x_refsource_OSVDB
36743
vdb-entry
x_refsource_OSVDB
25451
vdb-entry
x_refsource_BID
3070
third-party-advisory
x_refsource_SREASON
36740
vdb-entry
x_refsource_OSVDB
36765
vdb-entry
x_refsource_OSVDB
36761
vdb-entry
x_refsource_OSVDB
36750
vdb-entry
x_refsource_OSVDB
36759
vdb-entry
x_refsource_OSVDB
36766
vdb-entry
x_refsource_OSVDB
36746
vdb-entry
x_refsource_OSVDB
36744
vdb-entry
x_refsource_OSVDB
36758
vdb-entry
x_refsource_OSVDB
36751
vdb-entry
x_refsource_OSVDB
36757
vdb-entry
x_refsource_OSVDB
36756
vdb-entry
x_refsource_OSVDB
26586
third-party-advisory
x_refsource_SECUNIA
36739
vdb-entry
x_refsource_OSVDB
36747
vdb-entry
x_refsource_OSVDB
36764
vdb-entry
x_refsource_OSVDB
36753
vdb-entry
x_refsource_OSVDB
36745
vdb-entry
x_refsource_OSVDB
36742
vdb-entry
x_refsource_OSVDB
36748
vdb-entry
x_refsource_OSVDB
36763
vdb-entry
x_refsource_OSVDB
36749
vdb-entry
x_refsource_OSVDB
interworxcp-index-xss(36297)
vdb-entry
x_refsource_XF
36752
vdb-entry
x_refsource_OSVDB
36755
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now