Vulnerabilities > CVE-2007-3198 - Cross-Site Scripting vulnerability in Maran Blog

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
maran
exploit available

Summary

Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remote attackers to inject arbitrary web script or HTML via the id parameter.

Vulnerable Configurations

Part Description Count
Application
Maran
1

Exploit-Db

descriptionMaran PHP Blog 'comments.php' Cross-Site Scripting Vulnerability. CVE-2007-3198. Webapps exploit for php platform
idEDB-ID:32090
last seen2016-02-03
modified2008-07-21
published2008-07-21
reporterDr.Crash
sourcehttps://www.exploit-db.com/download/32090/
titleMaran PHP Blog 'comments.php' Cross-Site Scripting Vulnerability