Vulnerability CVE-2007-5403


Published: 2008-01-09   Modified: 2012-02-12

Description:
Multiple cross-site scripting (XSS) vulnerabilities in Layton HelpBox 3.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Forename, (2) Surname, (3) Telephone, and (4) Fax fields to writeenduserenduser.asp; the (5) Filter field to statsrequestypereport.asp; and the (6) sys_request_id parameter to requestattach.asp; and allow remote authenticated users to inject arbitrary web script or HTML via the (7) Asset, (8) Location, and (9) Problem fields to editrequestenduser.asp; the (10) Asset, (11) Asset Location, (12) Problem Desc, and (13) Solution Desc fields to editrequestuser.asp; and the (14) End User and (15) Description fields to usersearchrequests.asp. NOTE: vectors 5 and 6 do not require authentication to exploit.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

CVSS2 => (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.5/10
2.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Layton technology -> Helpbox 

 References:
http://www.securityfocus.com/bid/27187
http://secunia.com/secunia_research/2007-94/advisory/
http://secunia.com/advisories/27699
http://xforce.iss.net/xforce/xfdb/39543
http://xforce.iss.net/xforce/xfdb/39542
http://xforce.iss.net/xforce/xfdb/39541
http://xforce.iss.net/xforce/xfdb/39540
http://xforce.iss.net/xforce/xfdb/39537

Copyright 2024, cxsecurity.com

 

Back to Top