CVE-2007-5727
Last modified
CVE-2007-5727 is a vulnerability of currently unknown severity. Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag.. EPSS estimates a 1.92% chance of exploitation in the next 30 days.
Description
Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oneorzero | Oneorzero Helpdesk | 1.6.4.2 |
| Oneorzero | Oneorzero Helpdesk | 1.6.5.4 |
References
- http://secunia.com/advisories/27415Vendor Advisory
- http://secunia.com/advisories/27415Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5727?
How severe is CVE-2007-5727?
How do I fix CVE-2007-5727?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5721PHP remote file inclusion vulnerability in _theme/breadcrumb…
- CVE-2007-5722Stack-based buffer overflow in a certain ActiveX control in …
- CVE-2007-5723Heap-based buffer overflow in the samp_send function in nuau…
- CVE-2007-5724Multiple cross-site scripting (XSS) vulnerabilities in Omnis…
- CVE-2007-5725Multiple cross-site scripting (XSS) vulnerabilities in Smart…
- CVE-2007-5726Unspecified vulnerability in the Stream Control Transmission…
- CVE-2007-5728Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 t…
- CVE-2007-5729The NE2000 emulator in QEMU 0.8.2 allows local users to exec…
- CVE-2007-5730Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and…
- CVE-2007-5731Absolute path traversal vulnerability in Apache Jakarta Slid…
- CVE-2007-5732Directory traversal vulnerability in downloadfile.php in eLo…
- CVE-2007-5733Unrestricted file upload vulnerability in upload/upload.php …
Are you affected by CVE-2007-5727?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
