CVE-2007-1248

built2go News Manager Blog 1.0 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by the_Edit0r · textwebappsphp
https://www.exploit-db.com/exploits/29697
exploitdb WRITEUP VERIFIED
by the_Edit0r · textwebappsphp
https://www.exploit-db.com/exploits/29698

Scores

EPSS 0.0489
EPSS Percentile 89.4%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

built2go/news_manager_blog

Timeline

Published Mar 03, 2007
Tracked Since Feb 18, 2026