CVE-2007-3888 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 1.5% (pctl 74)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the search action, possibly related to the term parameter to index.php; or (2) an anonymous blog entry, possibly involving the (a) posted_by, (b) subject, and (c) content parameters to index.php; as demonstrated by the onmouseover attribute of certain elements. NOTE: some of these details are obtained from third party information.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.55% — more likely to be exploited than 74% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-07-18 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| insanely simple blog | insanely simple blog |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Insanely Simple Blog 0.4/0.5 - Cross-Site Scripting | 2007-07-17 |
References
- http://secunia.com/advisories/26105
- http://securityreason.com/securityalert/2904
- http://www.securityfocus.com/archive/1/473868/100/0/threaded
- http://www.securityfocus.com/bid/24934
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35448
- http://secunia.com/advisories/26105
- http://securityreason.com/securityalert/2904
- http://www.securityfocus.com/archive/1/473868/100/0/threaded
- http://www.securityfocus.com/bid/24934
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35448
→ the Explorer · watch your stack · NVD