Vulnerabilities > CVE-2007-2892 - Cross-Site Scripting vulnerability in Asp-Nuke 2.0.7

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
asp-nuke
exploit available

Summary

Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Configurations

Part Description Count
Application
Asp-Nuke
1

Exploit-Db

descriptionASP-Nuke 2.0.7 News.ASP Cross Site Scripting Vulnerability. CVE-2007-2892. Webapps exploit for php platform
idEDB-ID:30081
last seen2016-02-03
modified2007-05-24
published2007-05-24
reportervagrant
sourcehttps://www.exploit-db.com/download/30081/
titleASP-Nuke 2.0.7 News.ASP Cross-Site Scripting Vulnerability