MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php
Published Nov 15, 2007
4.3
MEDIUMCVSS 2.0
EPSS 1.71%
Description
Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php.
Affected products
No data.
OR
- ≤ 1.3.2
- ≤ 1.4.1
- ≤ 1.4.2
- ≤ 1.4.3
- ≤ 1.4.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (16)
- http://osvdb.org/38751 vdb-entryx_refsource_OSVDB
- http://osvdb.org/38752 vdb-entryx_refsource_OSVDB
- http://osvdb.org/38753 vdb-entryx_refsource_OSVDB
- http://osvdb.org/38754 vdb-entryx_refsource_OSVDB
- http://osvdb.org/42219 vdb-entryx_refsource_OSVDB
- http://osvdb.org/42220 vdb-entryx_refsource_OSVDB
- http://osvdb.org/42221 vdb-entryx_refsource_OSVDB
- http://osvdb.org/42222 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/27550 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://sourceforge.net/forum/forum.php?forum_id=752472 x_refsource_CONFIRMPatch
- http://sourceforge.net/project/shownotes.php?group_id=146822&release_id=552477 x_refsource_CONFIRM
- http://sourceforge.net/tracker/index.php?func=detail&aid=1753797&group_id=146822&atid=766508 x_refsource_CONFIRM
- http://www.securityfocus.com/bid/26551 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-5955 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38413 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38414 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 15, 2007
Updated Aug 7, 2024
Reserved Nov 14, 2007
Link CVE-2007-5985
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2007-5955 Assigner mitre
Published Nov 15, 2007
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2007-5955