CVE-2007-1390
UnknownEPSS 1.69%
Last modified
CVE-2007-1390 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in dynaliens 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) recherche.php3 or (2) ajouter.php3.. EPSS estimates a 1.69% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in dynaliens 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) recherche.php3 or (2) ajouter.php3.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dynaliens | Dynaliens | 2.0 |
| Dynaliens | Dynaliens | 2.1 |
References
- http://www.securityfocus.com/bid/22874Vendor Advisory
- http://www.securityfocus.com/bid/22874Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1390?
Multiple cross-site scripting (XSS) vulnerabilities in dynaliens 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) recherche.php3 or (2) ajouter.php3.
How severe is CVE-2007-1390?
Severity scoring for CVE-2007-1390 is pending analysis. The EPSS model estimates a 1.69% probability of exploitation in the next 30 days.
How do I fix CVE-2007-1390?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1383Integer overflow in the 16 bit variable reference counter in…9.8
- CVE-2007-1384Directory traversal vulnerability in torrent.cpp in KTorrent…
- CVE-2007-1385chunkcounter.cpp in KTorrent before 2.1.2 allows remote atta…
- CVE-2007-1387The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MP…
- CVE-2007-1388The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c …
- CVE-2007-1389dynaliens 2.0 and 2.1 allows remote attackers to bypass auth…
- CVE-2007-1391PHP remote file inclusion vulnerability in modules/abook/fol…
- CVE-2007-1392Directory traversal vulnerability in down.php in netForo! 0.…
- CVE-2007-1393PHP remote file inclusion vulnerability in mysave.php in Mag…
- CVE-2007-1394Direct static code injection vulnerability in startsession.p…
- CVE-2007-1395Incomplete blacklist vulnerability in index.php in phpMyAdmi…
- CVE-2007-1396The import_request_variables function in PHP 4.0.7 through 4…
Are you affected by CVE-2007-1390?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
