Vulnerabilities > CVE-2007-4079 - Cross-Site Scripting vulnerability in AlstraSoft SMS Text Messaging Enterprise
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft SMS Text Messaging Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) q parameter to (a) admin/membersearch.php, or (3) the userid parameter to (b) admin/edituser.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description AlstraSoft SMS Text Messaging Enterprise 2.0 admin/membersearch.php Multiple Parameter XSS. CVE-2007-4079 . Webapps exploit for php platform id EDB-ID:30367 last seen 2016-02-03 modified 2007-07-23 published 2007-07-23 reporter Lostmon source https://www.exploit-db.com/download/30367/ title AlstraSoft Sms Text Messaging Enterprise 2.0 admin/membersearch.php Multiple Parameter XSS description AlstraSoft SMS Text Messaging Enterprise 2.0 admin/edituser.php userid Parameter XSS. CVE-2007-4079 . Webapps exploit for php platform id EDB-ID:30368 last seen 2016-02-03 modified 2007-07-23 published 2007-07-23 reporter Lostmon source https://www.exploit-db.com/download/30368/ title AlstraSoft Sms Text Messaging Enterprise 2.0 admin/edituser.php userid Parameter XSS