Vulnerabilities > CVE-2007-0939 - Unspecified vulnerability in Microsoft Content Management Server 2001/2002
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS07-018.NASL |
description | The remote host contains a version of the Microsoft Content Management Server that is vulnerable to a security flaw that could allow a remote user to execute arbitrary code by sending a specially malformed HTTP request. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25026 |
published | 2007-04-11 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25026 |
title | MS07-018: Vulnerabilities in Microsoft Content Management Server Could Allow Remote Code Execution (925939) |
code |
|
Oval
accepted | 2015-08-10T04:00:20.657-04:00 | ||||||||||||||||
class | vulnerability | ||||||||||||||||
contributors |
| ||||||||||||||||
definition_extensions |
| ||||||||||||||||
description | Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability." | ||||||||||||||||
family | windows | ||||||||||||||||
id | oval:org.mitre.oval:def:1575 | ||||||||||||||||
status | accepted | ||||||||||||||||
submitted | 2007-04-11T08:08:51 | ||||||||||||||||
title | CMS Cross-Site Scripting and Spoofing Vulnerability | ||||||||||||||||
version | 13 |
References
- http://secunia.com/advisories/24819
- http://secunia.com/advisories/24819
- http://www.osvdb.org/34007
- http://www.osvdb.org/34007
- http://www.securityfocus.com/archive/1/466331/100/200/threaded
- http://www.securityfocus.com/archive/1/466331/100/200/threaded
- http://www.securityfocus.com/archive/1/466331/100/200/threaded
- http://www.securityfocus.com/archive/1/466331/100/200/threaded
- http://www.securityfocus.com/bid/22860
- http://www.securityfocus.com/bid/22860
- http://www.securitytracker.com/id?1017894
- http://www.securitytracker.com/id?1017894
- http://www.vupen.com/english/advisories/2007/1322
- http://www.vupen.com/english/advisories/2007/1322
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-018
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-018
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1575
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1575