// For flags

CVE-2007-2198

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cross-site scripting (XSS) vulnerability in LAN Management System (LMS) before 1.6.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving the OD parameter to contrib/formularz_przelewu_wplaty/druk.php.

Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en LAN Management System (LMS) anterior a 1.6.9 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados, posiblemente afectando al parámetro OD en contrib/formularz_przelewu_wplaty/druk.php.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-04-24 CVE Reserved
  • 2007-04-24 CVE Published
  • 2024-06-19 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Lan Management System
Search vendor "Lan Management System"
Lan Management System
Search vendor "Lan Management System" for product "Lan Management System"
1.5.6
Search vendor "Lan Management System" for product "Lan Management System" and version "1.5.6"
-
Affected