Vulnerability Description
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_calendar366_xss_fix_plugin.xml update.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jelsoft | Vbulletin | <= 3.6.6 |
References
- http://osvdb.org/35156
- http://www.vbulletin.com/forum/showthread.php?postid=1355012Patch
- http://osvdb.org/35156
- http://www.vbulletin.com/forum/showthread.php?postid=1355012Patch
FAQ
What is CVE-2007-2909?
CVE-2007-2909 is a vulnerability with a CVSS score of 3.5 (LOW). Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the ...
How severe is CVE-2007-2909?
CVE-2007-2909 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2909?
Check the references section above for vendor advisories and patch information. Affected products include: Jelsoft Vbulletin.