CVE-2007-2206

Properties

Published:
23.04.2007
Updated:
31.01.2008
Patch available:
Severity:
Medium
CVSS vector:
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Product:
Ripe Website Manager: Ripe Website Manager

Vulnerability description

Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a leading"<"<"in the ripeformpost parameter.

References:

BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/466673/100/0/threaded
BID: http://www.securityfocus.com/bid/23597
BUGTRAQ: http://archives.neohapsis.com/archives/bugtraq/2007-04/0384.html
http://john-martinelli.com/work/ripe.txt: http://john-martinelli.com/work/ripe.txt
FRSIRT: http://www.frsirt.com/english/advisories/2007/1519
SECUNIA: http://secunia.com/advisories/24984
XF: http://xforce.iss.net/xforce/xfdb/33817
SREASON: http://securityreason.com/securityalert/2602