Cross-site scripting (XSS) vulnerability in sample-forms/simple-contact-form-with-preview/simple-contact-form-with-preview.html in MitriDAT eMail Form Processor Pro allows remote attackers to inject arbitrary web script or HTML via the base_path parameter, possibly related to (1) formprocessorpro.php in the PHP version of the product, and (2) formprocessorpro.pl in the Perl version of the product.
References
Configurations
History
21 Nov 2024, 00:34
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/26225 - Vendor Advisory | |
References | () http://securityreason.com/securityalert/2961 - | |
References | () http://www.securityfocus.com/archive/1/474615/100/0/threaded - | |
References | () http://www.vupen.com/english/advisories/2007/2700 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/35695 - |
Information
Published : 2007-08-03 20:17
Updated : 2024-11-21 00:34
NVD link : CVE-2007-4144
Mitre link : CVE-2007-4144
CVE.ORG link : CVE-2007-4144
JSON object : View
Products Affected
mitridat
- form_processor_pro
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')