CVE-2007-3137
Webmaster Solutions Wmscms - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid parameter in index.php is affected, but this is incorrect.
Exploits (2)
exploitdb
WRITEUP
VERIFIED
by Glafkos Charalambous · textwebappsphp
https://www.exploit-db.com/exploits/30162
References (6)
Scores
EPSS
0.0493
EPSS Percentile
89.5%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
webmaster_solutions/wmscms
Timeline
Published
Jun 08, 2007
Tracked Since
Feb 18, 2026