Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-3299

Опубликовано: 20 июн. 2007
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
awffullfixed3.7.4final-1package

Примечания

  • awffull (a webalizer fork) does not have any cookie based authentication

  • or other sensitive data that could be leaked through this

EPSS

Процентиль: 73%
0.00792
Низкий

Связанные уязвимости

ubuntu
около 18 лет назад

Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.

nvd
около 18 лет назад

Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.

EPSS

Процентиль: 73%
0.00792
Низкий