CVE-2007-5370

Netwin Dnewsweb - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inject arbitrary web script or HTML via the (1) group or (2) utag parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Doz · textwebappscgi
https://www.exploit-db.com/exploits/30649

Scores

EPSS 0.0076
EPSS Percentile 73.1%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

netwin/dnewsweb

Timeline

Published Oct 11, 2007
Tracked Since Feb 18, 2026