CVE-2007-4711 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch 1.00 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage (2) mail and (3) name parameters in a show action to (a) form.php; the (4) language and (5) anzeigebreite parameters to (b) admin/header.php; and the (6) msg parameter to (c) install.php different vectors than CVE-2006-0706.
Reference
http://secunia.com/advisories/26662 http://securityreason.com/securityalert/3097 http://www.osvdb.org/36735 http://www.osvdb.org/36736 http://www.securityfocus.com/archive/1/478360/100/0/threaded http://www.securityfocus.com/archive/1/478803/100/0/threaded http://www.securityfocus.com/bid/25507 https://exchange.xforce.ibmcloud.com/vulnerabilities/36404
Share on: