CVE-2007-4115

IT!CMS 0.2 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtitle parameter to (1) lang-en.php, (2) menu-ed.php, or (3) titletext-ed.php.

Exploits (3)

exploitdb WRITEUP VERIFIED
by Aria-Security Team · textwebappsphp
https://www.exploit-db.com/exploits/30433
exploitdb WRITEUP VERIFIED
by Aria-Security Team · textwebappsphp
https://www.exploit-db.com/exploits/30434
exploitdb WRITEUP VERIFIED
by Aria-Security Team · textwebappsphp
https://www.exploit-db.com/exploits/30435

Scores

EPSS 0.0233
EPSS Percentile 84.6%

Classification

Status draft

Affected Products (1)

itcms/itcms

Timeline

Published Jul 31, 2007
Tracked Since Feb 18, 2026