CVE-2007-3596

inc/vul_check.inc in phpVideoPro before 0.8.8 permits non-alphanumeric characters in the sess_id parameter, which has unknown impact and remote attack vectors, probably cross-site scripting (XSS).
Configurations

Configuration 1 (hide)

cpe:2.3:a:izzysoft:phpvideopro:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:33

Type Values Removed Values Added
References () http://osvdb.org/36349 - () http://osvdb.org/36349 -
References () http://phpvideopro.cvs.sourceforge.net/phpvideopro/phpvideopro/inc/vul_check.inc?r1=1.10&r2=1.11 - () http://phpvideopro.cvs.sourceforge.net/phpvideopro/phpvideopro/inc/vul_check.inc?r1=1.10&r2=1.11 -
References () http://secunia.com/advisories/25815 - Vendor Advisory () http://secunia.com/advisories/25815 - Vendor Advisory
References () http://sourceforge.net/project/shownotes.php?release_id=518490&group_id=18639 - () http://sourceforge.net/project/shownotes.php?release_id=518490&group_id=18639 -
References () http://www.qumran.org/homes/izzy/software/pvp-dev/help/?topic=history - () http://www.qumran.org/homes/izzy/software/pvp-dev/help/?topic=history -
References () http://www.securityfocus.com/bid/24644 - Patch () http://www.securityfocus.com/bid/24644 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/35120 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/35120 -

Information

Published : 2007-07-06 18:30

Updated : 2025-04-09 00:30


NVD link : CVE-2007-3596

Mitre link : CVE-2007-3596

CVE.ORG link : CVE-2007-3596


JSON object : View

Products Affected

izzysoft

  • phpvideopro