{"api_version":"1","generated_at":"2026-07-23T11:51:11+00:00","cve":"CVE-2007-2600","urls":{"html":"https://cve.report/CVE-2007-2600","api":"https://cve.report/api/cve/CVE-2007-2600.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2600","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2600"},"summary":{"title":"CVE-2007-2600","description":"Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-05-11 10:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/23905","name":"http://www.securityfocus.com/bid/23905","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"TutorialCMS Search.PHP SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.exploit-db.com/exploits/3887","name":"https://www.exploit-db.com/exploits/3887","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"TutorialCMS 1.00 - 'search.php?search' SQL Injection - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/35897","name":"http://osvdb.org/35897","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/35896","name":"http://osvdb.org/35896","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/35895","name":"http://osvdb.org/35895","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/35894","name":"http://osvdb.org/35894","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/35892","name":"http://osvdb.org/35892","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/35893","name":"http://osvdb.org/35893","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/1742","name":"http://www.vupen.com/english/advisories/2007/1742","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34215","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34215","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2600","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2600","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2600","vulnerable":"1","versionEndIncluding":"1.00","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wavelink_media","cpe5":"tutorialcms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:42:33.423Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"35893","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35893"},{"name":"23905","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/23905"},{"name":"ADV-2007-1742","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1742"},{"name":"35894","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35894"},{"name":"35897","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35897"},{"name":"35896","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35896"},{"name":"tutorialcms-multiple-xss(34215)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34215"},{"name":"35895","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35895"},{"name":"35892","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35892"},{"name":"3887","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/3887"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-05-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-10T00:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"35893","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35893"},{"name":"23905","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/23905"},{"name":"ADV-2007-1742","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1742"},{"name":"35894","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35894"},{"name":"35897","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35897"},{"name":"35896","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35896"},{"name":"tutorialcms-multiple-xss(34215)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34215"},{"name":"35895","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35895"},{"name":"35892","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35892"},{"name":"3887","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/3887"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-2600","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"35893","refsource":"OSVDB","url":"http://osvdb.org/35893"},{"name":"23905","refsource":"BID","url":"http://www.securityfocus.com/bid/23905"},{"name":"ADV-2007-1742","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1742"},{"name":"35894","refsource":"OSVDB","url":"http://osvdb.org/35894"},{"name":"35897","refsource":"OSVDB","url":"http://osvdb.org/35897"},{"name":"35896","refsource":"OSVDB","url":"http://osvdb.org/35896"},{"name":"tutorialcms-multiple-xss(34215)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34215"},{"name":"35895","refsource":"OSVDB","url":"http://osvdb.org/35895"},{"name":"35892","refsource":"OSVDB","url":"http://osvdb.org/35892"},{"name":"3887","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/3887"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-2600","datePublished":"2007-05-11T10:00:00.000Z","dateReserved":"2007-05-11T00:00:00.000Z","dateUpdated":"2024-08-07T13:42:33.423Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-05-11 10:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wavelink_media:tutorialcms:*:*:*:*:*:*:*:*","versionEndIncluding":"1.00","matchCriteriaId":"9D5F39AF-D5AE-46EF-86F7-9FD14B897399"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2600","Ordinal":"1","Title":"CVE-2007-2600","CVE":"CVE-2007-2600","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2600","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php.","Type":"Description","Title":"CVE-2007-2600"},{"CveYear":"2007","CveId":"2600","Ordinal":"2","NoteData":"2007-05-11","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2600","Ordinal":"3","NoteData":"2017-10-09","Type":"Other","Title":"Modified"}]}}}