CVE Vulnerabilities

CVE-2007-0407

Published: Jan 23, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain Black WebGUI before 7.3.5 (beta) allows remote attackers to inject arbitrary web script or HTML via the username parameter during anonymous registration, a different vector than CVE-2007-0308. NOTE: it is possible that a separate WikiPage titles issue was also fixed.

Affected Software

Name Vendor Start Version End Version
Webgui Plain_black 6.3.0 (including) 6.3.0 (including)
Webgui Plain_black 6.4.0 (including) 6.4.0 (including)
Webgui Plain_black 6.5.0 (including) 6.5.0 (including)
Webgui Plain_black 6.5.1 (including) 6.5.1 (including)
Webgui Plain_black 6.5.2 (including) 6.5.2 (including)
Webgui Plain_black 6.5.3 (including) 6.5.3 (including)
Webgui Plain_black 6.5.4 (including) 6.5.4 (including)
Webgui Plain_black 6.5.5 (including) 6.5.5 (including)
Webgui Plain_black 6.5.6 (including) 6.5.6 (including)
Webgui Plain_black 6.6.0 (including) 6.6.0 (including)
Webgui Plain_black 6.6.1 (including) 6.6.1 (including)
Webgui Plain_black 6.6.2 (including) 6.6.2 (including)
Webgui Plain_black 6.6.3 (including) 6.6.3 (including)
Webgui Plain_black 6.6.4 (including) 6.6.4 (including)
Webgui Plain_black 6.6.5 (including) 6.6.5 (including)
Webgui Plain_black 6.7.0 (including) 6.7.0 (including)
Webgui Plain_black 6.7.1 (including) 6.7.1 (including)
Webgui Plain_black 6.7.2 (including) 6.7.2 (including)
Webgui Plain_black 6.7.3 (including) 6.7.3 (including)
Webgui Plain_black 6.7.4 (including) 6.7.4 (including)
Webgui Plain_black 6.7.5 (including) 6.7.5 (including)
Webgui Plain_black 6.7.6 (including) 6.7.6 (including)
Webgui Plain_black 6.8.1 (including) 6.8.1 (including)
Webgui Plain_black 6.8.2 (including) 6.8.2 (including)
Webgui Plain_black 6.8.3 (including) 6.8.3 (including)
Webgui Plain_black 6.8.4 (including) 6.8.4 (including)
Webgui Plain_black 6.8.5 (including) 6.8.5 (including)
Webgui Plain_black 6.8.6 (including) 6.8.6 (including)
Webgui Plain_black 7.2.3 (including) 7.2.3 (including)
Webgui Plain_black 7.3.4_beta (including) 7.3.4_beta (including)

References