Vulnerabilities > CVE-2007-1965 - Unspecified vulnerability in Exv2 Content Management System
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://marc.info/?l=bugtraq&m=117570977117962&w=2
- http://marc.info/?l=bugtraq&m=117570977117962&w=2
- http://www.majorsecurity.de/index_2.php?major_rls=major_rls38
- http://www.majorsecurity.de/index_2.php?major_rls=major_rls38
- http://www.securityfocus.com/bid/23314
- http://www.securityfocus.com/bid/23314