CVE-2007-4760

Severity
4.3MEDIUM
EPSS
0.3%
top 45.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 1

Description

The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 7.5 can generate HTML documents that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably the same issue as CVE-2007-3503.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wv5h-grg4-29jw: The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 72022-05-01
CVEList
CVE-2007-4760: The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 72007-09-08

💥Exploits & PoCs

1
Exploit-DB
Alcatel Lucent Omnivista 4760 - Multiple Cross-Site Scripting Vulnerabilities2007-10-18