Vulnerabilities > CVE-2007-2632 - Cross-Site Scripting vulnerability in PHP Multi User Randomizer PHP Multi User Randomizer 2006.09.13

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
php-multi-user-randomizer
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web script or HTML via (1) the edit_plugin parameter to configure_plugin.tpl.php, or (2) certain array parameters to web/phpinfo.php, as demonstrated by 1[] or a[].

Vulnerable Configurations

Part Description Count
Application
Php_Multi_User_Randomizer
1

Exploit-Db

descriptionPHP Multi User Randomizer 2006.09.13 Configure_Plugin.TPL.PHP Cross-Site Scripting Vulnerability. CVE-2007-2632. Webapps exploit for php platform
idEDB-ID:30022
last seen2016-02-03
modified2007-05-10
published2007-05-10
reporterthe_Edit0r
sourcehttps://www.exploit-db.com/download/30022/
titlePHP Multi User Randomizer 2006.09.13 Configure_Plugin.TPL.PHP Cross-Site Scripting Vulnerability