CVE-2007-3291

Livecms - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by g00ns · perlwebappsphp
https://www.exploit-db.com/exploits/4082

Scores

EPSS 0.0429
EPSS Percentile 88.7%

Classification

CWE
CWE-79
Status draft

Affected Products (6)

livecms/livecms
livecms/livecms
livecms/livecms
livecms/livecms
livecms/livecms
livecms/livecms

Timeline

Published Jun 20, 2007
Tracked Since Feb 18, 2026