Vulnerabilities > CVE-2007-3485 - Unspecified vulnerability in Yandex Yandex.Server

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Yandex.Server allow remote attackers to inject arbitrary web script or HTML via the (1) query or (2) within parameter to the default URI.

Vulnerable Configurations

Part Description Count
Application
Yandex
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/112945/yandex-xss.txt
idPACKETSTORM:112945
last seen2016-12-05
published2012-05-22
reporterMustLive
sourcehttps://packetstormsecurity.com/files/112945/Yandex.Server-2010-9.0-Enterprise-Cross-Site-Scripting.html
titleYandex.Server 2010 9.0 Enterprise Cross Site Scripting