33717vdb entry
http://osvdb.org/33717 CVE-2007-0925
Community Server - 'SearchResults.aspx' Cross-Site Scripting
Record summary
CVE-2007-0925 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCommunity Server - 'SearchResults.aspx' Cross-Site ScriptingExploitDB exploitby BL4CKNot analyzed1 file
References
62241Third-party advisory
http://securityreason.com/securityalert/2241 20070209 XSS in communityserver !mailing list
http://www.securityfocus.com/archive/1/459848/100/0/threaded 22529vdb entry
http://www.securityfocus.com/bid/22529 communityserver-searchresults-xss(32444)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/32444 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-0925