Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this may overlap CVE-2007-1965.
References
Configurations
History
No history.
Information
Published : 2007-08-15 19:17
Updated : 2024-02-04 17:13
NVD link : CVE-2007-4365
Mitre link : CVE-2007-4365
CVE.ORG link : CVE-2007-4365
JSON object : View
Products Affected
exv2
- content_management_system
CWE