CVE-2007-1151

LoveCMS 1.4 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error.

Exploits (1)

exploitdb WRITEUP VERIFIED
by laurent gaffie · textwebappsphp
https://www.exploit-db.com/exploits/29639

Scores

EPSS 0.0052
EPSS Percentile 66.5%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

lovecms/lovecms

Timeline

Published Mar 02, 2007
Tracked Since Feb 18, 2026