CVE Vulnerabilities

CVE-2007-1848

Published: Apr 03, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in admin/classes/ui.dta.php in Drake CMS allows remote attackers to inject arbitrary web script or HTML via the desc[][title] field. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated We do not consider security reports valid until the first official release of Drake CMS.

Affected Software

Name Vendor Start Version End Version
Drake_cms Drake_team 0.3.7 (including) 0.3.7 (including)
Drake_cms Drake_team 0.3.7_beta (including) 0.3.7_beta (including)

References