Cross-site Scripting Vulnerabilities in FileRun by FileRun
CVE-2007-2470

Currently unrated

Key Information:

Vendor

Filerun

Status
Vendor
CVE Published:
2 May 2007

What is CVE-2007-2470?

Multiple cross-site scripting vulnerabilities exist in index.php of FileRun 1.0 and earlier. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML through the manipulation of parameters including page, module, or section. Attackers exploiting this flaw could potentially execute malicious scripts in the context of the user’s session, compromising sensitive information and leading to unauthorized actions within the affected web application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.