← All CVEs

CVE-2007-6312

medium · 4.3

Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 allows remote attackers to inject arbitrary web script or HTML via the username field.

4.3
CVSS
15.9%
EPSS (exploit prob.)
97th
EPSS percentile
2007-12-11
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
websenseenterpise6.3
websenseenterpise6.3.1
websensereporting_tools6.3
websensereporting_tools6.3.1
websenseweb_security_suite6.3
websenseweb_security_suite6.3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-6312