Cross-Site Scripting Vulnerability in ISS Proventia Network IPS Products
CVE-2007-3830

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
17 July 2007

Badges

👾 Exploit Exists🟡 Public PoC

Summary

An injection flaw exists in the alert.php component of the ISS Proventia Network IPS, specifically in versions GX5108 1.3 and GX5008 1.5. This vulnerability enables remote attackers to inject malicious web scripts or HTML code through the 'reminder' parameter. If exploited, this flaw could lead to unauthorized actions and data exposure, compromising the security and integrity of affected systems.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.