CVE-2007-3299

Publication date 20 June 2007

Last updated 17 July 2025


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.

Status

Package Ubuntu Release Status
awffull 8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
7.04 feisty Ignored end of life, was needed
6.10 edgy Not in release
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities