Unrated severityNVD Advisory· Published Jun 20, 2007· Updated Apr 23, 2026
CVE-2007-3299
CVE-2007-3299
Description
Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.stedee.id.au/flyspray/task/10nvdPatch
- osvdb.org/37478nvd
- secunia.com/advisories/25776nvd
- www.securityfocus.com/bid/24587nvd
- www.stedee.id.au/awffull/changesnvd
- www.stedee.id.au/pipermail/awffull/2007-May/000363.htmlnvd
- www.stedee.id.au/pipermail/awffull/2007-May/000364.htmlnvd
- www.stedee.id.au/pipermail/awffull/2007-May/000365.htmlnvd
- www.vupen.com/english/advisories/2007/2250nvd
News mentions
0No linked articles in our index yet.