CVE-2007-4588

Description from NVD

Multiple cross-site scripting (XSS) vulnerabilities in InterWorx Hosting Control Panel (InterWorx-CP) Server Admin Level (NodeWorx) 3.0.2 (1) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php; and allow remote authenticated users to inject arbitrary web script or HTML via the PATH_INFO to (2) nodeworx.php, (3) users.php, (4) lang.php, (5) themes.php, (6) setup.php, (7) siteworx.php, (8) packages.php, (9) backup.php, (10) import.php, (11) scriptworx.php, (12) resellers.php, (13) reseller-packages.php, (14) http.php, (15) mail.php, (16) ftp.php, (17) mysql.php, (18) sshd.php, (19) nfs.php, (20) cron.php, (21) ip.php, (22) firewall.php, (23) updates.php, (24) rrd.php, or (25) cluster.php.

Information Acquisition Date:2022-08-31T16:40Z
CVSS 2.0: 4.3 MEDIUM CVSS 3.x: 0.0 None

▼ CVSS2 Vec AV:N/AC:M/Au:N/C:N/I:P/A:N

NVD References

 25451
     source:BID
     tags:
 http://www.hackerscenter.com/archive/view.asp?id=27884
     source:MISC
     tags:
 http://interworx.com/forums/showthread.php?t=2501
     source:CONFIRM
     tags:
 26586
     source:SECUNIA
     tags:
 3070
     source:SREASON
     tags:
 36762
     source:OSVDB
     tags:
 36745
     source:OSVDB
     tags:
 36739
     source:OSVDB
     tags:
 36752
     source:OSVDB
     tags:
 36759
     source:OSVDB
     tags:
 36747
     source:OSVDB
     tags:
 36763
     source:OSVDB
     tags:
 36761
     source:OSVDB
     tags:
 36746
     source:OSVDB
     tags:
 36753
     source:OSVDB
     tags:
 36764
     source:OSVDB
     tags:
 36758
     source:OSVDB
     tags:
 36757
     source:OSVDB
     tags:
 36743
     source:OSVDB
     tags:
 36765
     source:OSVDB
     tags:
 36750
     source:OSVDB
     tags:
 36748
     source:OSVDB
     tags:
 36740
     source:OSVDB
     tags:
 36751
     source:OSVDB
     tags:
 36755
     source:OSVDB
     tags:
 36742
     source:OSVDB
     tags:
 36766
     source:OSVDB
     tags:
 36744
     source:OSVDB
     tags:
 36749
     source:OSVDB
     tags:
 36756
     source:OSVDB
     tags:
 interworx-nodeworx-multiple-file-include(36301)
     source:XF
     tags:
 interworxcp-index-xss(36297)
     source:XF
     tags:
 20070826 InterWorx-CP Multiple HTML Injections Vulnerabilitie
     source:BUGTRAQ
     tags:

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag: MySQL(4 tweets) PHP(74 tweets)


▼ Show Information from Twitter(149)

▼ Show Information from Twitter(149)


GitHub Search Results: Up to 10
NameURL
No Data

GitHub Search Results: Up to 10
NameURL
No Data

2022/08/31 Score : 0
Added Har-sia Database : 2022/08/11
Last Modified : 2022/08/31
Highest Scored Date : 2022/08/11
Highest Score : 74