NVD
- Id
- 55727
- Name
- CVE-2007-3577
- Description
- PHPIDS before 20070703 does not properly handle use of the substr method in (1) document.location.search and (2) document.referrer; (3) certain use of document.location.hash; (4) certain "window[eval" and similar expressions; (5) certain Function expressions; (6) certain "=" expressions, as demonstrated by a "whatever="something"" sequence; and (7) certain "with" expressions, which allows remote attackers to inject arbitrary web script.
- Reject
- CVSS Version
- 2
- CVSS Score
- 4.3
- Severity
- Medium
- CVSS Base Score
- 4.3
- CVSS Impact Subscore
- 2.9
- CVSS Exploit Subscore
- 8.6
- CVSS Vector
- (AV:N/AC:M/Au:N/C:N/I:P/A:N)
- Pub Date
- 2017-01-07
- Published
- 2007-07-05
- Modified Date
- 2008-11-15
- Seq
- 2007-3577