CVE-2007-5727
Last modified
CVE-2007-5727 is a vulnerability of currently unknown severity. Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag.. EPSS estimates a 1.92% chance of exploitation in the next 30 days.
Description
Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oneorzero | Oneorzero Helpdesk | 1.6.4.2 |
| Oneorzero | Oneorzero Helpdesk | 1.6.5.4 |
References
- http://secunia.com/advisories/27415Vendor Advisory
- http://secunia.com/advisories/27415Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5727?
How severe is CVE-2007-5727?
How do I fix CVE-2007-5727?
Are you affected by CVE-2007-5727?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
