CVE-2007-3339

CVSS 4.3 - MEDIUM
Description

Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3) FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm and (c) blog/include/common/comfinish.cfm.

Affected Products
15
Vendor Product Version
fusetalk fusetalk 2.0
fusetalk fusetalk 2.0
fusetalk fusetalk 2.0
fusetalk fusetalk 2.0
fusetalk fusetalk 3.0
fusetalk fusetalk 3.0
fusetalk fusetalk 3.0
fusetalk fusetalk 3.0
fusetalk fusetalk 3.0
fusetalk fusetalk 3.2
fusetalk fusetalk 4.0
fusetalk fusetalk 4.0
fusetalk fusetalk 4.0
fusetalk fusetalk 4.0
fusetalk fusetalk 4.0
Weakness Types
CWE-79
CVE Information
CVE ID:
CVE-2007-3339
Published:
2007-06-21
Modified:
2026-04-23
CVSS Score:
4.3
Severity:
MEDIUM
Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N
Affected Vendors
fusetalk
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL