CVE-2007-0705
Summary
| CVE | CVE-2007-0705 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-02-04 00:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-zone scripting vulnerability in Sleipnir 2.49 and earlier, and Portable Sleipnir 2.45 and earlier, allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data. NOTE: some of these details are obtained from third party information. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fenrir | Portable Sleipnir | All | All | All | All |
| Application | Fenrir | Sleipnir | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/32977 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| JVN#93700808: Sleipnir の RSSバーにおけるセキュリティゾーンの扱いに関する脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| IPA 独立行政法人 情報処理推進機構 | af854a3a-2127-422b-91ae-364da2661108 | www.ipa.go.jp | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Sleipnir RSS Bar Incorrect Security Zone - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Sleipnir におけるセキュリティゾーンの扱いに関する脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | www.fenrir.co.jp | |
| JVN:JVN#93700808 | MITRE | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.