CVE-2007-4348
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el servicio CAD de IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 y 5.4.1.2 para Windows permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante peticiones HTTP al puerto 1581, lo cual genera entradas de registro en el fichero dsmerror.log, el cual es accesible a través de cierta inferfaz web.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-08-14 CVE Reserved
- 2007-10-29 CVE Published
- 2024-08-07 CVE Updated
- 2024-10-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/26221 | Vdb Entry | |
http://www.securitytracker.com/id?1018868 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/3635 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38125 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/27013 | 2017-07-29 | |
http://secunia.com/secunia_research/2007-75/advisory | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Tivoli Storage Manager Client Search vendor "Ibm" for product "Tivoli Storage Manager Client" | <= 5.3.5.3 Search vendor "Ibm" for product "Tivoli Storage Manager Client" and version " <= 5.3.5.3" | windows |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Storage Manager Client Search vendor "Ibm" for product "Tivoli Storage Manager Client" | <= 5.4.1.2 Search vendor "Ibm" for product "Tivoli Storage Manager Client" and version " <= 5.4.1.2" | windows |
Affected
|