Web Wiz · Webwiz · CVE-2007-3202
Name of the Vulnerable Software and Affected Versions:
Webwiz (affected versions not specified)
Description:
A cross-site scripting (XSS) issue exists in the rich text editor of Webwiz, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via URL-encoded HTML composed of a frameset where a frame has a SRC attribute pointing to a JavaScript document.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.