CVE-2007-4192
Last modified
CVE-2007-4192 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in IDE Group DVD Rental System (DRS) 5.1 before 20070801 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: it is not clear whether IDE Group updates all DRS installations in its role as an application service provider. EPSS estimates a 1.22% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in IDE Group DVD Rental System (DRS) 5.1 before 20070801 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: it is not clear whether IDE Group updates all DRS installations in its role as an application service provider. If so, then this issue should not be included in CVE.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ide Group | Dvd Rental System Drs | 5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4192?
How severe is CVE-2007-4192?
How do I fix CVE-2007-4192?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4186PHP remote file inclusion vulnerability in admin.tour_toto.p…
- CVE-2007-4187Multiple eval injection vulnerabilities in the com_search co…
- CVE-2007-4188Session fixation vulnerability in Joomla! before 1.0.13 (aka…
- CVE-2007-4189Multiple cross-site scripting (XSS) vulnerabilities in Jooml…
- CVE-2007-4190CRLF injection vulnerability in Joomla! before 1.0.13 (aka S…
- CVE-2007-4191Panda Antivirus 2008 stores service executables under the pr…
- CVE-2007-4193Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2007-4194Guidance Software EnCase 5.0 allows user-assisted remote att…
- CVE-2007-4195Use-after-free vulnerability in ext2fs.c in Brian Carrier Th…
- CVE-2007-4196icat in Brian Carrier The Sleuth Kit (TSK) before 2.09 misin…
- CVE-2007-4197icat in Brian Carrier The Sleuth Kit (TSK) before 2.09 omits…
- CVE-2007-4198The fs_data_put_str function in ntfs.c in fls in Brian Carri…
Are you affected by CVE-2007-4192?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
