CVE-2007-3137

WmsCMS <= 2.0 - Cross-Site Scripting via 4print.asp Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-3137. PoCs published by Glafkos Charalambous.

AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in WmsCMS 2.0, where user-supplied input is not properly sanitized. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.

Description

Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid parameter in index.php is affected, but this is incorrect.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Glafkos Charalambous · textwebappsphp
https://www.exploit-db.com/exploits/30162

The provided text describes a cross-site scripting (XSS) vulnerability in WmsCMS 2.0, where user-supplied input is not properly sanitized. It includes example URLs demonstrating the vulnerability but does not contain executable exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: WmsCMS 2.0
No auth needed
Prerequisites: Access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/13739

This advisory details XSS and SQL injection vulnerabilities in WMSCMS, specifically in parameters like 'search', 'sbr', and 'pid' in default.asp and printpage.asp. It provides technical details on affected parameters and attack vectors but does not include functional exploit code.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Reliable
Target: WMSCMS (all versions)
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24365
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2789
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34763
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/470758/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25583
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37144

Scores

EPSS 0.0181
EPSS Percentile 75.7%

Details

CWE
CWE-79
Status published
Products (1)
webmaster_solutions/wmscms 2.0
Published Jun 08, 2007
Tracked Since Feb 18, 2026