Return to CVE list

CVE-2007-4874

4.3
Medium

CVE-2007-4874

cve@mitre.org
Modified

Description

Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) l_username parameter to admin/layout2b.php, and the (2) backurl parameter to comment.php.

Exploits

306172007-09-25webappsPHP

SimpNews 2.41.3 - 'l_username' Cross-Site Scripting

By Jesper Jurcenoks
306182007-09-25webappsPHP

SimpNews 2.41.3 - 'backurl' Cross-Site Scripting

By Jesper Jurcenoks