CVE-2007-2592
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to de/pda/dev_logon.asp and (2) multiple unspecified vectors in (a) usrmgr/registerAccount.asp, (b) de/create_account.asp, and other files.
Múltiples vulnerabilidades secuencias de comandos en sitios cruzados (XSS) en el Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107 y 6.6.2.2, posiblemente involucrando al Novell Groupwise Mobile Server y al Nokia Intellisync Wireless Email Express, permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro (1) username en el de/pda/dev_logon.asp y (2) múltiples vectores sin especificar en el (a) usrmgr/registerAccount.asp, (b) de/create_account.asp y otros archivos.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-05-10 CVE Reserved
- 2007-05-11 CVE Published
- 2024-07-06 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://osvdb.org/34515 | Vdb Entry | |
http://osvdb.org/34516 | Vdb Entry | |
http://osvdb.org/34517 | Vdb Entry | |
http://secunia.com/advisories/26199 | Third Party Advisory | |
http://securityreason.com/securityalert/2689 | Third Party Advisory | |
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5005120.html | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/468048/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/23889 | Vdb Entry | |
http://www.securitytracker.com/id?1018454 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/1727 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/2657 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34187 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.sec-consult.com/289.html | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/25212 | 2018-10-16 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nokia Search vendor "Nokia" | Groupwise Mobile Server Search vendor "Nokia" for product "Groupwise Mobile Server" | * | - |
Affected
| ||||||
Nokia Search vendor "Nokia" | Intellisync Mobile Suite Search vendor "Nokia" for product "Intellisync Mobile Suite" | 6.4.31.2 Search vendor "Nokia" for product "Intellisync Mobile Suite" and version "6.4.31.2" | - |
Affected
| ||||||
Nokia Search vendor "Nokia" | Intellisync Mobile Suite Search vendor "Nokia" for product "Intellisync Mobile Suite" | 6.6.0.107 Search vendor "Nokia" for product "Intellisync Mobile Suite" and version "6.6.0.107" | - |
Affected
| ||||||
Nokia Search vendor "Nokia" | Intellisync Mobile Suite Search vendor "Nokia" for product "Intellisync Mobile Suite" | 6.6.2.2 Search vendor "Nokia" for product "Intellisync Mobile Suite" and version "6.6.2.2" | - |
Affected
| ||||||
Nokia Search vendor "Nokia" | Intellisync Wireless Email Express Search vendor "Nokia" for product "Intellisync Wireless Email Express" | * | - |
Affected
|