Vulnerability Description
Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this may overlap CVE-2007-1965.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Exv2 | Content Management System | <= 2.0.5 |
References
- http://osvdb.org/36479
- http://securityreason.com/securityalert/3021
- http://www.i-s-o.org/security.txt
- http://www.securityfocus.com/archive/1/476287/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35992
- http://osvdb.org/36479
- http://securityreason.com/securityalert/3021
- http://www.i-s-o.org/security.txt
- http://www.securityfocus.com/archive/1/476287/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35992
FAQ
What is CVE-2007-4365?
CVE-2007-4365 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this may...
How severe is CVE-2007-4365?
CVE-2007-4365 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4365?
Check the references section above for vendor advisories and patch information. Affected products include: Exv2 Content Management System.