CVE-2007-5120

N/A Unknown
Published: September 27, 2007 Modified: April 23, 2026
View on NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML via the (1) group and (2) members parameters in (a) NewGroup.jsp; the (3) edittime parameter in (b) Edit.jsp; the (4) edittime, (5) author, and (6) link parameters in (c) Comment.jsp; the (7) loginname, (8) wikiname, (9) fullname, and (10) email parameters in (d) UserPreferences.jsp and (e) Login.jsp; the (11) r1 and (12) r2 parameters in (f) Diff.jsp; and the (13) changenote parameter in (g) PageInfo.jsp.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/26961
Source: cve@mitre.org
Patch Vendor Advisory
http://www.securityfocus.com/bid/25803
Source: cve@mitre.org
Exploit Patch
http://secunia.com/advisories/26961
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://securityreason.com/securityalert/3167
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ecyrd.com/~jalkanen/JSPWiki/2.4.104/ChangeLog
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/480570/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/25803
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/36766
Source: af854a3a-2127-422b-91ae-364da2661108

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.4%
82th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

jspwiki