CVE Vulnerabilities

CVE-2007-2976

Published: Jun 01, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Centrinity FirstClass 8.3 and earlier, and Server and Internet Services 8.0 and earlier, do not properly handle a URL with a null (%00) character, which allows remote attackers to conduct cross-site scripting (XSS) attacks. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected Software

Name Vendor Start Version End Version
Firstclass Cetrinity * 8.3 (including)
Server_and_internet_services Cetrinity * 8.0 (including)

References