Security Advisory

CVE-2007-5370

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-10-11 10:00:00
Last updated 2024-08-07 15:31:57
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inject arbitrary web script or HTML via the (1) group or (2) utag parameter.