CVE-2007-3653
Fascript Faname - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) key or (2) desc parameter to index.php, or (3) the name parameter to page.php.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Jesper Jurcenoks · textwebappsphp
https://www.exploit-db.com/exploits/32004
exploitdb
WRITEUP
VERIFIED
by Jesper Jurcenoks · textwebappsphp
https://www.exploit-db.com/exploits/32005
Scores
EPSS
0.0029
EPSS Percentile
52.4%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
fascript/faname
Timeline
Published
Jul 09, 2008
Tracked Since
Feb 18, 2026