Vulnerabilities > CVE-2007-2532 - Cross-Site Scripting vulnerability in Obie Website Mini web Shop 2

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
obie-website
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) to (1) sendmail.php or (2) order_form.php, different vectors than CVE-2006-6734.

Vulnerable Configurations

Part Description Count
Application
Obie_Website
1

Exploit-Db

  • descriptionObieWebsite Mini Web Shop 2 order_form.php PATH_INFO Parameter XSS. CVE-2007-2532. Webapps exploit for php platform
    idEDB-ID:29956
    last seen2016-02-03
    modified2007-05-02
    published2007-05-02
    reporterCorryL
    sourcehttps://www.exploit-db.com/download/29956/
    titleObieWebsite Mini Web Shop 2 order_form.php PATH_INFO Parameter XSS
  • descriptionObieWebsite Mini Web Shop 2 sendmail.php PATH_INFO Parameter XSS. CVE-2007-2532. Webapps exploit for php platform
    idEDB-ID:29957
    last seen2016-02-03
    modified2007-05-02
    published2007-05-02
    reporterCorryL
    sourcehttps://www.exploit-db.com/download/29957/
    titleObieWebsite Mini Web Shop 2 sendmail.php PATH_INFO Parameter XSS