CVE-2007-5472

medium

Description

Cross-site scripting (XSS) vulnerability in the Server component in CA Host-Based Intrusion Prevention System (HIPS) before 8.0.0.93 allows remote attackers to inject arbitrary web script or HTML via requests that are written to logs for later display in the log viewer.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/37285

http://www.vupen.com/english/advisories/2007/3547

http://www.securityfocus.com/bid/26134

http://www.securityfocus.com/archive/1/482536/100/0/threaded

http://supportconnectw.ca.com/public/cahips/infodocs/cahips-secnotice.asp

http://securitytracker.com/id?1018839

http://secunia.com/advisories/27301

http://osvdb.org/37998

Details

Source: Mitre, NVD

Published: 2007-10-22

Updated: 2025-04-09

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00656