CVE-2007-1576
Last modified
CVE-2007-1576 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Search (only Gecko engine driven Browsers), and (5) Notes modules; the (6) Mail summary page; and unspecified other files.. EPSS estimates a 1.84% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Search (only Gecko engine driven Browsers), and (5) Notes modules; the (6) Mail summary page; and unspecified other files.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phprojekt | Phprojekt | 5.2 |
References
- http://security.gentoo.org/glsa/glsa-200706-07.xmlThird Party Advisory
- http://www.nruns.de/security_advisory_phprojekt_xss_and_filter_evasion.phpBroken Link, Vendor Advisory
- http://www.phprojekt.com/index.php?name=News&file=article&sid=276Broken Link, Patch, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200706-07.xmlThird Party Advisory
- http://www.nruns.de/security_advisory_phprojekt_xss_and_filter_evasion.phpBroken Link, Vendor Advisory
- http://www.phprojekt.com/index.php?name=News&file=article&sid=276Broken Link, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1576?
How severe is CVE-2007-1576?
How do I fix CVE-2007-1576?
Are you affected by CVE-2007-1576?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
