Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-2801

Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) err and (2) warn parameters. NOTE: the vendor disputes the significance of the issue, stating that "eTicket is not designed to work with register_globals On."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.113
EPSS Ranking 93.3%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2007-2801
  • Eticket » Eticket » Version: 1.5.5
    cpe:2.3:a:eticket:eticket:1.5.5
  • Eticket » Eticket » Version: 1.5.5.1
    cpe:2.3:a:eticket:eticket:1.5.5.1


Contact Us

Shodan ® - All rights reserved