{"api_version":"1","generated_at":"2026-07-23T06:34:17+00:00","cve":"CVE-2007-2805","urls":{"html":"https://cve.report/CVE-2007-2805","api":"https://cve.report/api/cve/CVE-2007-2805.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2805","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2805"},"summary":{"title":"CVE-2007-2805","description":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) ticketID, (2) view, and (3) fuse parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-05-22 19:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34390","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34390","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels-team.blogspot.com/2007/05/clientexec-xss-vuln.html","name":"http://pridels-team.blogspot.com/2007/05/clientexec-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"-UNSECURED SYSTEMS-: ClientExec XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/37526","name":"http://osvdb.org/37526","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/24061","name":"http://www.securityfocus.com/bid/24061","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ClientExec Index.PHP Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2805","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2805","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2805","vulnerable":"1","versionEndIncluding":"3.0_beta2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"clientexec","cpe5":"clientexec","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:49:57.308Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"37526","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37526"},{"name":"clientexec-index-xss(34390)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34390"},{"name":"24061","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24061"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels-team.blogspot.com/2007/05/clientexec-xss-vuln.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-05-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) ticketID, (2) view, and (3) fuse parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"37526","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37526"},{"name":"clientexec-index-xss(34390)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34390"},{"name":"24061","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24061"},{"tags":["x_refsource_MISC"],"url":"http://pridels-team.blogspot.com/2007/05/clientexec-xss-vuln.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-2805","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) ticketID, (2) view, and (3) fuse parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"37526","refsource":"OSVDB","url":"http://osvdb.org/37526"},{"name":"clientexec-index-xss(34390)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34390"},{"name":"24061","refsource":"BID","url":"http://www.securityfocus.com/bid/24061"},{"name":"http://pridels-team.blogspot.com/2007/05/clientexec-xss-vuln.html","refsource":"MISC","url":"http://pridels-team.blogspot.com/2007/05/clientexec-xss-vuln.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-2805","datePublished":"2007-05-22T19:00:00.000Z","dateReserved":"2007-05-22T00:00:00.000Z","dateUpdated":"2024-08-07T13:49:57.308Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-05-22 19:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:clientexec:clientexec:*:*:*:*:*:*:*:*","versionEndIncluding":"3.0_beta2","matchCriteriaId":"27154A95-7242-4E2C-9692-21C62EC86430"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2805","Ordinal":"1","Title":"CVE-2007-2805","CVE":"CVE-2007-2805","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2805","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) ticketID, (2) view, and (3) fuse parameters.","Type":"Description","Title":"CVE-2007-2805"},{"CveYear":"2007","CveId":"2805","Ordinal":"2","NoteData":"2007-05-22","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2805","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}