CVE-2007-3017
CVE-2007-3017
The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admin/worklist/worklist_edit.asp.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/30299unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://osvdb.org/39745http://secunia.com/advisories/26063http://securityreason.com/securityalert/2900https://exchange.xforce.ibmcloud.com/vulnerabilities/35399http://www.redteam-pentesting.de/advisories/rt-sa-2007-006.phphttp://www.securityfocus.com/archive/1/473627/100/0/threadedhttp://www.securityfocus.com/bid/24898