← Back

CVE-2007-4896

nvd nist
Published: Sep 14, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in admin/header.php in Toms Gaestebuch 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang[adminseite], (2) lang[ueberschrift], or (3) einst[metachar] parameter, different vectors than CVE-2007-4711.

Affected (2)

Toms Gastenbuch
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Toms Seiten.at
Version 1.00
Version 1.01

References (12)

Timeline

No history available yet.