CVE-2007-4595

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
29/08/2007
Last modified:
29/07/2017

Description

Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.12 allows remote attackers to inject arbitrary web script or HTML in certain circumstances involving (1) lack of charset specification within a META element or (2) a META element that specifies an unrecognized charset, which trigger automatic character set recognition by the web browser, as demonstrated by improper handling of UTF-7 data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:the_seasar_foundation:mayaa:*:*:*:*:*:*:*:* 1.1.11 (including)