CVE-2007-6726
Last modified
CVE-2007-6726 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.. EPSS estimates a 3.45% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Struts | 2.0.9 |
| Dojotoolkit | Dojo | 0.4.1 |
| Dojotoolkit | Dojo | 0.4.2 |
References
- http://www.dojotoolkit.org/0-4-3-and-updated-0-4-1-0-4-2-buildsPatch, Vendor Advisory
- http://www.dojotoolkit.org/releaseNotes/0.4.3Patch, Vendor Advisory
- https://issues.apache.org/struts/browse/WW-2134Vendor Advisory
- http://www.dojotoolkit.org/0-4-3-and-updated-0-4-1-0-4-2-buildsPatch, Vendor Advisory
- http://www.dojotoolkit.org/releaseNotes/0.4.3Patch, Vendor Advisory
- https://issues.apache.org/struts/browse/WW-2134Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6726?
How severe is CVE-2007-6726?
How do I fix CVE-2007-6726?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6720libmikmod 3.1.9 through 3.2.0, as used by MikMod, SDL-mixer,…
- CVE-2007-6721The Legion of the Bouncy Castle Java Cryptography API before…
- CVE-2007-6722Vidalia bundle before 0.1.2.18, when running on Windows and …
- CVE-2007-6723TorK before 0.22, when running on Windows and Mac OS X, inst…
- CVE-2007-6724Vidalia bundle before 0.1.2.18, when running on Windows, ins…
- CVE-2007-6725The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and …
- CVE-2007-6727SQL injection vulnerability in topic.php in KerviNet Forum 1…
- CVE-2007-6728Cross-site scripting (XSS) vulnerability in XMB 1.5 allows r…
- CVE-2007-6729Cross-site scripting (XSS) vulnerability in the web manageme…
- CVE-2007-6730Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2007-6731Extended Module Player (XMP) 2.5.1 and earlier allow remote …
- CVE-2007-6732Multiple buffer overflows in the dtt_load function in loader…
Are you affected by CVE-2007-6726?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
