Vulnerabilities > CVE-2007-4239 - Unspecified vulnerability in C-Sam Onewallet 210070620071.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Cross-site scripting (XSS) vulnerability in user/forgotPassStep2.jsp in the admin interface in C-SAM oneWallet 210_07062007;1.0 allows remote attackers to inject arbitrary web script or HTML via the loginID parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Statements
contributor | Viral Shah |
lastmodified | 2007-08-09 |
organization | C-SAM |
statement | The version on which this vulnerability has been detected is a pre-release (non-commercial) version of the OneWallet platform. The current version of the product does not have the vulnerability in question (namely, XSS TYPE 1). C-SAM takes utmost care in ensuring the security of its products and will proactively release patches from time to time to address such issues. |
References
- http://www.securityfocus.com/archive/1/475732/100/0/threaded
- http://www.securityfocus.com/archive/1/475732/100/0/threaded
- http://www.securityfocus.com/bid/25224
- http://www.securityfocus.com/bid/25224
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35838
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35838