CVE Database
/

CVE-2007-4589

Back to search

CVE-2007-4589

Published: Aug 29, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Webmaster Level (SiteWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php; and allow remote authenticated users to inject arbitrary web script or HTML via the PATH_INFO to (2) siteworx.php, (3) users.php, (4) ftp.php, (5) mysql.php, (6) domains.php, (7) htaccess.php, (8) scriptworx.php, (9) stats.php, (10) backup.php, (11) restore.php, and (12) httpd.php; and unspecified vectors to (13) cron.php and (14) prefs.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

36778
vdb-entry
x_refsource_OSVDB
25451
vdb-entry
x_refsource_BID
3070
third-party-advisory
x_refsource_SREASON
36772
vdb-entry
x_refsource_OSVDB
36775
vdb-entry
x_refsource_OSVDB
36771
vdb-entry
x_refsource_OSVDB
36776
vdb-entry
x_refsource_OSVDB
36773
vdb-entry
x_refsource_OSVDB
36780
vdb-entry
x_refsource_OSVDB
36779
vdb-entry
x_refsource_OSVDB
36768
vdb-entry
x_refsource_OSVDB
36774
vdb-entry
x_refsource_OSVDB
26586
third-party-advisory
x_refsource_SECUNIA
36777
vdb-entry
x_refsource_OSVDB
36769
vdb-entry
x_refsource_OSVDB
36767
vdb-entry
x_refsource_OSVDB
interworxcp-index-xss(36297)
vdb-entry
x_refsource_XF
36770
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now