« Volver al listado

CVE-2007-4523

Estado: ModificadaBaja (3.5)—

Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php, probably involving the Title or textarea field as reachable through admin/pages/new_page.php.

Leer descripción completaMostrar menos

NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-4523",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-08-25T00:17:00.000",
  "references": [
    {
      "url": "http://osvdb.org/38444",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/38445",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/38446",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/38447",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/38448",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/38449",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/3058",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/477320/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/25406",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36179",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/38444",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/38445",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/38446",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/38447",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/38448",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/38449",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/3058",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/477320/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/25406",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36179",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php, probably involving the Title or textarea field as reachable through admin/pages/new_page.php.  NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de inyección SQL en Ripe Website Manager 0.8.9 y versiones anteriores permite a usuarios remotos autenticados inyectar scripts web o HTML de su elección  mediante uno o mas de los siguientes vectores:  (1) parámetro id en (a) pages/delete_page.php, (b) navigation/delete_menu.php, y (c) navigation/delete_item.php en admin/; parámetros  (2) menu_id, (3) name, (3) page_id, y (4) url en (d) admin/navigation/do_new_item.php; parámetro  (5) new_menuname en (e) admin/navigation/do_new_nav.php; y (6) parámetro2 area1, name, y url en (f) admin/pages/do_new_page.php, probablemente involucrando el campo Title ó textarea como alcanzable a través de admin/pages/new_page.php.\r\nNOTA: La información original no señala con precisión qué vectores se asocian a una iyección SQL frente a XSS."
    }
  ],
  "lastModified": "2026-06-16T22:44:15.420",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ripe_website_manager:ripe_website_manager:0.8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B66BE0A0-5DB0-4BB2-BE65-1C369F226666"
            },
            {
              "criteria": "cpe:2.3:a:ripe_website_manager:ripe_website_manager:0.8.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF7AE17A-374E-42AD-ADAE-4A3EC0CBC59E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}