CVE-2007-4811 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to inject arbitrary web script or HTML via (1) the val parameter to alphabet.php in an alpha.albums action or the PATH_INFO to (2) random.php or (3) admin/hidden.php.
Reference
http://osvdb.org/38402 http://osvdb.org/38403 http://osvdb.org/38404 http://securityreason.com/securityalert/3110 http://www.securityfocus.com/archive/1/478871/100/0/threaded http://www.securityfocus.com/bid/25599 https://exchange.xforce.ibmcloud.com/vulnerabilities/36517
Share on: