PT-2007-2601 · Webapp · Webapp
Published
2007-02-28
·
Updated
2017-07-29
·
CVE-2007-1174
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WebAPP versions prior to 20070214
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to unspecified fields in user profiles.
Recommendations
For versions prior to 20070214, update to a version released after 20070214 to resolve the issue. As a temporary workaround, consider restricting access to user profiles until the update is applied. Avoid using unspecified fields in user profiles that may be related to the XSS vulnerabilities until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webapp