MEDIUM · 4.9

CVE-2007-2907

Unspecified vulnerability in SSL-Explorer before 0.2.13 allows remote authenticated users to enter redirect URLs containing (1) JavaScript or (2) HTTP headers via an unspecified vector, possibly the f...

Vulnerability Description

Unspecified vulnerability in SSL-Explorer before 0.2.13 allows remote authenticated users to enter redirect URLs containing (1) JavaScript or (2) HTTP headers via an unspecified vector, possibly the forwardTo parameter to redirect.do. NOTE: the impact might be cross-site scripting (XSS) or HTTP request smuggling.

CVSS Score

4.9

MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Ssl-ExplorerSsl-Explorer<= 0.2.12

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-2907?

CVE-2007-2907 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Unspecified vulnerability in SSL-Explorer before 0.2.13 allows remote authenticated users to enter redirect URLs containing (1) JavaScript or (2) HTTP headers via an unspecified vector, possibly the f...

How severe is CVE-2007-2907?

CVE-2007-2907 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2907?

Check the references section above for vendor advisories and patch information. Affected products include: Ssl-Explorer Ssl-Explorer.