4.3
CVSSv2

CVE-2007-2739

Published: 17/05/2007 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in xajax prior to 0.2.5 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

xajax xajax

Vendor Advisories

Debian Bug report logs - #426103 New upstream release with security fixes Package: php-xajax; Maintainer for php-xajax is Debian QA Group <packages@qadebianorg>; Source for php-xajax is src:php-xajax (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, 26 May 2007 10:15:06 UTC Severity: ...
It was discovered that php-xajax, a library to develop Ajax applications, did not sufficiently sanitise URLs, which allows attackers to perform cross-site scripting attacks by using malicious URLs For the stable distribution (etch) this problem has been fixed in version 024-2+etch1 For the testing (lenny) and unstable (sid) distributions th ...