« Volver al listado

CVE-2007-3839

Estado: ModificadaMedia (4)—

Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 010306 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-3839",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-07-17T22:30:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/26120",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24923",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/data/vulnerabilities/exploits/24923.txt",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/26120",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24923",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/data/vulnerabilities/exploits/24923.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 010306 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the avatar parameter.  NOTE: this may be related to the tracker program in the Janitor package.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en takeprofedit.php in TBDev.NET DR 010306 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de un javascript: URI en el parámetro avatar. NOTA: esto podría estar relacionado con el programa perseguidor en el paquete Janitor. NOTA: la procedencia de esta información es desconocida; los detalles han sido obtenidos a partir de la información de terceros. \r\n"
    }
  ],
  "lastModified": "2026-06-16T22:42:52.073",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tbdev.net:dr:11-10-05-beta-sf1_1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7582DC29-9CB2-44D0-A001-494B32B39CAC"
            },
            {
              "criteria": "cpe:2.3:a:tbdev.net:dr:16-12-05-beta-1_161:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1F28217-F905-45E4-BEE5-34FD2EED971F"
            },
            {
              "criteria": "cpe:2.3:a:tbdev.net:dr:010306:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "676A299F-004E-4C7A-B1E0-B51249057E66"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}