4.3
CVSSv2

CVE-2007-6126

Published: 26/11/2007 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable through a view action to the top-level index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

project alumni project alumni 1.0.8

project alumni project alumni

Exploits

project-alumni sql injection & xss author : tomplixsee tomplixsee@yahoocoid ------------------------------------------------------------------------------------------------------------- affected software version : project alumni v109, v108, or lower?? download : sourceforgenet/projects/project-alumni/ vulnerability ======== ...