Back to Database
Status published
Medium
CVE-2007-5477
Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod 0.48...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod 0.48 Half-Life Dedicated Server plugin allows remote attackers to inject arbitrary web script or HTML via the redir parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-5477
Credits & Attribution
No credits recorded in the NVD database.
References
More from valve software
View All →CVE-2006-0734
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server...
Medium
4
CVE-2004-0724
The Half-Life engine before July 7 2004 allows remote attackers...
Medium
5
CVE-2003-1325
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server...
Medium
5.2
CVE-2002-0964
Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause...
Medium
5
CVE-2001-0964
Buffer overflow in client for Half-Life 1.1.0.8 and earlier allows...
High
7.5
Affected Vendor
valve software
View all reports →Affected Software
half-life dedicated server, webmod plugin
Vulnerable Versions:
0.48
Timeline
Official Publish:
October 16th, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.