Vulnerability Description
Cross-site scripting (XSS) vulnerability in Bandersnatch 0.4 allows remote attackers to inject arbitrary JavaScript via a Jabber resource name and possibly other data items, which are stored in conversation logs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bandersnatch | Bandersnatch | 0.4 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/26202Vendor Advisory
- http://www.osvdb.org/38269
- http://www.portcullis-security.com/182.php
- http://www.portcullis-security.com/uplds/advisories/Bandersnatch%20-%2007-004.tx
- http://www.securityfocus.com/bid/25094
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35407
- http://secunia.com/advisories/26202Vendor Advisory
- http://www.osvdb.org/38269
- http://www.portcullis-security.com/182.php
- http://www.portcullis-security.com/uplds/advisories/Bandersnatch%20-%2007-004.tx
- http://www.securityfocus.com/bid/25094
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35407
FAQ
What is CVE-2007-3910?
CVE-2007-3910 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in Bandersnatch 0.4 allows remote attackers to inject arbitrary JavaScript via a Jabber resource name and possibly other data items, which are stored in conver...
How severe is CVE-2007-3910?
CVE-2007-3910 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3910?
Check the references section above for vendor advisories and patch information. Affected products include: Bandersnatch Bandersnatch.