inc/vul_check.inc in phpVideoPro before 0.8.8 permits non-alphanumeric characters in the sess_id parameter, which has unknown impact and remote attack vectors, probably cross-site scripting (XSS).
References
Configurations
History
21 Nov 2024, 00:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/36349 - | |
References | () http://phpvideopro.cvs.sourceforge.net/phpvideopro/phpvideopro/inc/vul_check.inc?r1=1.10&r2=1.11 - | |
References | () http://secunia.com/advisories/25815 - Vendor Advisory | |
References | () http://sourceforge.net/project/shownotes.php?release_id=518490&group_id=18639 - | |
References | () http://www.qumran.org/homes/izzy/software/pvp-dev/help/?topic=history - | |
References | () http://www.securityfocus.com/bid/24644 - Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/35120 - |
Information
Published : 2007-07-06 18:30
Updated : 2025-04-09 00:30
NVD link : CVE-2007-3596
Mitre link : CVE-2007-3596
CVE.ORG link : CVE-2007-3596
JSON object : View
Products Affected
izzysoft
- phpvideopro
CWE