| Vulnerability Name: | CVE-2007-6726 (CCN-49884) | ||||||||
| Assigned: | 2007-05-15 | ||||||||
| Published: | 2007-05-15 | ||||||||
| Updated: | 2017-08-17 | ||||||||
| Summary: | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-79 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2007-6726 Source: CONFIRM Type: Patch, Vendor Advisory http://www.dojotoolkit.org/0-4-3-and-updated-0-4-1-0-4-2-builds Source: CONFIRM Type: Patch, Vendor Advisory http://www.dojotoolkit.org/2007/05/26/0-4-3-released-0-4-2-and-0-4-1-users-should-upgrade-immediately Source: CCN Type: Dojo Web site 0.4.3 Release Notes Source: CONFIRM Type: Patch, Vendor Advisory http://www.dojotoolkit.org/releaseNotes/0.4.3 Source: CCN Type: OSVDB ID: 54011 Dojo src/io/xip_client.html XSS Source: CCN Type: OSVDB ID: 54012 Dojo src/io/xip_server.html XSS Source: BID Type: UNKNOWN 34660 Source: CCN Type: BID-34660 Dojo Multiple Cross Site Scripting Vulnerabilities Source: XF Type: UNKNOWN dojo-xipclient-xipserver-xss(49884) Source: XF Type: UNKNOWN dojo-xipclient-xipserver-xss(49884) Source: CCN Type: Apache Struts JIRA Bug WW-2134 Upgrade Dojo from 0.4.2 to 0.4.3 to address possible XSS Issues Source: CONFIRM Type: Vendor Advisory https://issues.apache.org/struts/browse/WW-2134 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||