Vulnerabilities > CVE-2007-4297 - HTML Injection vulnerability in Dersimiz Haber Ekleme Modulu Yorumkaydet.ASP

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
aspindir

Summary

Multiple cross-site scripting (XSS) vulnerabilities in yorumkaydet.asp in Dersimiz Haber Ekleme Modulu allow remote attackers to inject arbitrary web script or HTML via the (1) yazan, (2) mail, and (3) yorum parameters. NOTE: some of these details are obtained from third party information. See http://www.securityfocus.com/bid/25250 for additional information (vendor website)

Vulnerable Configurations

Part Description Count
Application
Aspindir
1