Unknown
CVE-2007-4760
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
The javadoc tool in Cosminexus Developer’s Kit for Java in Cosminexus 7 and 7.5 can generate HTML documents that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably the same issue as CVE-2007-3503.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- ucosminexus application server enterprise 07 00,
- ucosminexus application server enterprise 07 00 01,
- ucosminexus application server enterprise 07 00 02,
- ucosminexus application server enterprise 07 00 03,
- ucosminexus application server enterprise 07 10,
- ucosminexus application server enterprise 07 10 01,
- ucosminexus application server enterprise 7 20,
- ucosminexus application server enterprise 7 20 01,
- ucosminexus application server standard 07 00,
- ucosminexus application server standard 07 00 01,
- ucosminexus application server standard 07 00 02,
- ucosminexus application server standard 07 00 03,
- ucosminexus application server standard 07 10,
- ucosminexus application server standard 7 10 01,
- ucosminexus application server standard 7 20,
- ucosminexus application server standard 7 20 01,
- ucosminexus developer standard 07 00,
- ucosminexus developer standard 07 00 01,
- ucosminexus developer standard 07 00 02,
- ucosminexus developer standard 07 00 03,
- ucosminexus developer standard 07 10,
- ucosminexus developer standard 07 10 01,
- ucosminexus developer standard 07 20,
- ucosminexus developer standard 07 20 01,
- ucosminexus developer standard 07 50,
- ucosminexus service platform 07 00,
- ucosminexus service platform 07 00 01,
- ucosminexus service platform 07 00 02,
- ucosminexus service platform 07 00 03,
- ucosminexus service platform 07 10,
- ucosminexus service platform 07 10 01,
- ucosminexus service platform 07 20,
- ucosminexus service platform 7 20 01
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: