PT-2007-6657 · Rnote · Rnote

Published

2007-10-23

·

Updated

2008-11-15

·

CVE-2007-5648

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions rNote version 0.9.7.5
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via the d or the u parameter in the rnote.php file.
Recommendations For rNote version 0.9.7.5, avoid using the d and u parameters in the rnote.php file until a fix is available. As a temporary workaround, consider restricting access to the rnote.php file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5648

Affected Products

Rnote