PT-2007-4273 · Centrinity · Centrinity Server/Internet Services+1

Published

2007-06-01

·

Updated

2017-07-29

·

CVE-2007-2976

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Centrinity FirstClass versions 8.3 and earlier Centrinity Server and Internet Services versions 8.0 and earlier
Description The issue arises from improper handling of a URL with a null ("%00") character, allowing remote attackers to conduct cross-site scripting (XSS) attacks.
Recommendations For Centrinity FirstClass versions 8.3 and earlier, update to a version later than 8.3 to resolve the issue. For Centrinity Server and Internet Services versions 8.0 and earlier, update to a version later than 8.0 to resolve the issue. As a temporary workaround, consider restricting access to URLs that may contain null characters until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2976

Affected Products

Centrinity Firstclass
Centrinity Server/Internet Services