CVE-2007-0437
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3) the PAGE parameter to showsource.csp in csp/samples/; and allow remote authenticated users to inject arbitrary web script or HTML via (4) the ERROR parameter to csp/samples/xmlclasseserror.csp, and unspecified vectors in (5) object.csp and (6) lotteryhistory.csp in csp/samples/.
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en las secuencias de comandos ejemplo de Cache' Server Page (CSP) en InterSystems Cache' permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del (1) parámetro TO en loop.csp, (2) el parámetro VALUE en cookie.csp, y (3) el parámetro PAGE en showsource.csp en csp/samples/; y permite a usuarios remotos validados inyectar secuencias de comandos web o HTML a través del (4) parámetro ERROR en csp/samples/xmlclasseserror.csp, y vectores no especificados en (5) object.csp y (6) lotteryhistory.csp en csp/samples/.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-01-23 CVE Reserved
- 2007-08-20 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.cpni.gov.uk/Products/alerts/2928.aspx | X_refsource_misc | |
http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf | X_refsource_misc | |
http://www.mwrinfosecurity.com/news/1658.html | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Intersystems Search vendor "Intersystems" | Cache Database Search vendor "Intersystems" for product "Cache Database" | * | - |
Affected
|