« Volver al listado

CVE-2007-3254

Estado: ModificadaBaja (3.5)—

Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the Content-Type HTTP header; or (4) the name of an uploaded file. NOTE: items 3 and 4 also affect the same version numbers of Xythos Digital Locker (XDL). Some or all vectors might also affect Xythos WebFile Server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-3254",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-06-27T18:30:00.000",
  "references": [
    {
      "url": "http://osvdb.org/37621",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/37622",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/37623",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/37624",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25783",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/2845",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1018291",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1018292",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/472275/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24521",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-004.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35083",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/37621",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/37622",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/37623",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/37624",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25783",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/2845",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1018291",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1018292",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/472275/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24521",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-004.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35083",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the Content-Type HTTP header; or (4) the name of an uploaded file.  NOTE: items 3 and 4 also affect the same version numbers of Xythos Digital Locker (XDL). Some or all vectors might also affect Xythos WebFile Server."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Xythos Enterprise Document Manager (XEDM) anterior a 5.0.25.8, y 6.x anterior a 6.0.46.1,permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML de su elección mediante (1) un nombre de Workflow guardado; (2) un nombre de Workflow, relacionado con el borrado de una plantilla de Workflow; (3) la cabecera HTTP Content-Type; o (4) el nombre de un fichero subido. NOTA: los puntos 3 y 4 también afectan a los mismos números de versión de Xythos Digital Locker (XDL). Algunos o todos los vectores también afectan a Xythos WebFile Server."
    }
  ],
  "lastModified": "2026-06-16T22:41:21.653",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:xythos:enterprise_document_manager:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A884B8B1-D617-44E8-B707-D5FEB3DC6E47"
            },
            {
              "criteria": "cpe:2.3:a:xythos:enterprise_document_manager:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E370848C-21C2-437B-9138-C5CFE9669732"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}