PT-2007-7323 · Falcon · Falcon Series One Cms

Mhz91

·

Published

2007-12-20

·

Updated

2017-09-29

·

CVE-2007-6489

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Falcon Series One CMS version 1.4.3
Description The issue allows remote attackers to inject arbitrary web script or HTML via the gb mail, gb name, and gb text parameters in a guestbook action to "index.php", and unspecified other vectors. This can lead to cross-site scripting (XSS) attacks.
Recommendations For Falcon Series One CMS version 1.4.3, as a temporary workaround, consider restricting access to the guestbook action in "index.php" and avoid using the gb mail, gb name, and gb text parameters until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-6489

Affected Products

Falcon Series One Cms