Vulnerabilities > CVE-2007-2880 - Cross-Site Scripting vulnerability in Digiappz Digirez 3.4

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
digiappz

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Digirez 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Room_name parameter to room/info_book.asp or the (2) curYear parameter to room/week.asp.

Vulnerable Configurations

Part Description Count
Application
Digiappz
1