CVE-2007-6461
Flyspray 0.9.9-0.9.9.3 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject arbitrary web script or HTML via (1) the query string in an index action, related to the savesearch JavaScript function; and (2) the details parameter in a details action, related to the History tab and the getHistory JavaScript function.
Scores
EPSS
0.0029
EPSS Percentile
51.7%
Classification
CWE
CWE-79
Status
draft
Affected Products (4)
flyspray/flyspray
flyspray/flyspray
flyspray/flyspray
flyspray/flyspray
Timeline
Published
Dec 20, 2007
Tracked Since
Feb 18, 2026