Unrated severityNVD Advisory· Published Jan 18, 2007· Updated Jun 16, 2026
CVE-2007-0302
CVE-2007-0302
Description
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:instantasp:instantasp:4.1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:instantasp:instantasp:4.1.0:*:*:*:*:*:*:*
- (no CPE)range: = 4.1.0
Patches
Vulnerability mechanics
References
8News mentions
0No linked articles in our index yet.