Vulnerabilities > CVE-2007-2732 - Cross-Site Scripting vulnerability in Jetbox CMS 2.1
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter to view/search/; or the (2) companyname, (3) country, (4) email, (5) firstname, (6) middlename, (7) required, (8) surname, or (9) title parameter to view/supplynews/.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Jetbox CMS 2.1 view/search/ path Parameter XSS. CVE-2007-2732. Webapps exploit for php platform id EDB-ID:30041 last seen 2016-02-03 modified 2007-05-15 published 2007-05-15 reporter Mikhail Markin source https://www.exploit-db.com/download/30041/ title Jetbox CMS 2.1 - view/search/ path Parameter XSS description Jetbox CMS 2.1 view/supplynews/ Multiple Parameter XSS. CVE-2007-2732. Webapps exploit for php platform id EDB-ID:30042 last seen 2016-02-03 modified 2007-05-15 published 2007-05-15 reporter Mikhail Markin source https://www.exploit-db.com/download/30042/ title Jetbox CMS 2.1 - view/supplynews Multiple Parameter XSS