Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inject arbitrary web script or HTML via the (1) group or (2) utag parameter.
References
Configurations
History
21 Nov 2024, 00:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/37651 - | |
References | () http://secunia.com/advisories/27163 - | |
References | () http://securityreason.com/securityalert/3208 - | |
References | () http://www.securityfocus.com/archive/1/481865/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/25981 - | |
References | () http://www.vupen.com/english/advisories/2007/3452 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/37031 - |
Information
Published : 2007-10-11 10:17
Updated : 2024-11-21 00:37
NVD link : CVE-2007-5370
Mitre link : CVE-2007-5370
CVE.ORG link : CVE-2007-5370
JSON object : View
Products Affected
netwin
- dnewsweb
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')