CVE-2007-4512

Sophos Anti-Virus for Windows <6.5.8,7.0.1 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Sophos Anti-Virus for Windows 6.x before 6.5.8 and 7.x before 7.0.1 allows remote attackers to inject arbitrary web script or HTML via an archive with a file that matches a virus signature and has a crafted filename that is not properly handled by the print function in SavMain.exe.

Scores

EPSS 0.0069
EPSS Percentile 71.5%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

sophos/anti-virus < 6.5.4_r2

Timeline

Published Sep 10, 2007
Tracked Since Feb 18, 2026