CVE-2007-5480
Innovaage Innovashop - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in InnovaAge InnovaShop allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to msg.jsp, and the (2) contentid parameter to tc/contents/home001.jsp.
Exploits (2)
References (6)
Scores
EPSS
0.0362
EPSS Percentile
87.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
innovaage/innovashop
Timeline
Published
Oct 16, 2007
Tracked Since
Feb 18, 2026