4.3
CVSSv2

CVE-2007-5692

Published: 29/10/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 445
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in SiteBar 3.3.8 allow remote malicious users to inject arbitrary web script or HTML via (1) the lang parameter to integrator.php; (2) the token parameter in a New Password action, (3) the nid_acl parameter in a Folder Properties action, or (4) the uid parameter in a Modify User action to command.php; or (5) the target parameter to index.php, different vectors than CVE-2006-3320.

Vulnerable Product Search on Vulmon Subscribe to Product

sitebar sitebar 3.3.8

Vendor Advisories

Several remote vulnerabilities have been discovered in sitebar, a web based bookmark manager written in PHP The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-5491 A directory traversal vulnerability in the translation module allows remote authenticated users to chmod arbitrary files to 0777 via ...

Exploits

source: wwwsecurityfocuscom/bid/26126/info SiteBar is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input These issues include: - A local file-include vulnerability - Multiple arbitrary-script-code-execution vulnerabilities - Multiple cross-site scripting vulnerabilit ...
source: wwwsecurityfocuscom/bid/26126/info SiteBar is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input These issues include: - A local file-include vulnerability - Multiple arbitrary-script-code-execution vulnerabilities - Multiple cross-site scripting vulnerabilities - ...
source: wwwsecurityfocuscom/bid/26126/info SiteBar is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input These issues include: - A local file-include vulnerability - Multiple arbitrary-script-code-execution vulnerabilities - Multiple cross-site scripting vulnerabilities ...