CVE-2007-3189

Just For Fun Network Management System 0.8.3 - Cross-Site Scripting via User Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3189. PoCs published by Tim Brown.

AI-analyzed exploit summary The provided text describes multiple vulnerabilities in JFFNMS, including XSS, SQL injection, and information disclosure, but does not contain functional exploit code. It references a SecurityFocus BID and outlines potential attack vectors without technical implementation details.

Description

Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Tim Brown · textwebappsphp
https://www.exploit-db.com/exploits/30172

The provided text describes multiple vulnerabilities in JFFNMS, including XSS, SQL injection, and information disclosure, but does not contain functional exploit code. It references a SecurityFocus BID and outlines potential attack vectors without technical implementation details.

Classification
Writeup 80%
Attack Type
Xss | Sqli | Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Just For Fun Network Management and Monitoring System (JFFNMS) versions prior to 0.8.4-pre3
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1374
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/471039/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26769
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24414
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25587
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=118151087109711&w=2

Scores

EPSS 0.0397
EPSS Percentile 89.1%

Details

Status published
Products (1)
jffnms/just_for_fun_network_management_system 0.8.3
Published Jun 12, 2007
Tracked Since Feb 18, 2026