Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php, probably involving the Title or textarea field as reachable through admin/pages/new_page.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ripe Website Manager | Ripe Website Manager | 0.8.4 |
References
- http://osvdb.org/38444
- http://osvdb.org/38445
- http://osvdb.org/38446
- http://osvdb.org/38447
- http://osvdb.org/38448
- http://osvdb.org/38449
- http://securityreason.com/securityalert/3058
- http://www.securityfocus.com/archive/1/477320/100/0/threaded
- http://www.securityfocus.com/bid/25406
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36179
- http://osvdb.org/38444
- http://osvdb.org/38445
- http://osvdb.org/38446
- http://osvdb.org/38447
- http://osvdb.org/38448
FAQ
What is CVE-2007-4523?
CVE-2007-4523 is a vulnerability with a CVSS score of 3.5 (LOW). Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following v...
How severe is CVE-2007-4523?
CVE-2007-4523 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4523?
Check the references section above for vendor advisories and patch information. Affected products include: Ripe Website Manager Ripe Website Manager.