CVE-2007-4587 Information

Description

Cross-site scripting (XSS) vulnerability in Easy Software Cafeteria escafeWeb (aka Tuigwaa) 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors possibly related to the setting of option.nopage.create in tuigwaa.properties.

Reference

http://jvn.jp/jp/JVN2382276964/index.html http://osvdb.org/37147 http://secunia.com/advisories/26577 http://www.escafe.org/main/Security http://www.securityfocus.com/bid/25447 https://exchange.xforce.ibmcloud.com/vulnerabilities/36264

Share on: