CVE-2007-5304
Yannick Tanguy Else IF Cms - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) repertimage parameter to utilisateurs/vousetesbannis.php, the (2) elseifvotetxtresultatduvote parameter to utilisateurs/votesresultats.php, and the (3) elseifforumtxtmenugeneraleduforum parameter to moduleajouter/depot/adminforum.php.
Exploits (1)
References (8)
Scores
EPSS
0.0492
EPSS Percentile
89.4%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
yannick_tanguy/else_if_cms
Timeline
Published
Oct 09, 2007
Tracked Since
Feb 18, 2026