{"api_version":"1","generated_at":"2026-07-23T06:00:13+00:00","cve":"CVE-2007-3101","urls":{"html":"https://cve.report/CVE-2007-3101","api":"https://cve.report/api/cve/CVE-2007-3101.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3101","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3101"},"summary":{"title":"CVE-2007-3101","description":"Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.","state":"PUBLISHED","assigner":"redhat","published_at":"2007-06-18 10:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=544","name":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=544","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/25618","name":"http://secunia.com/advisories/25618","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Apache MyFaces Tomahawk \"autoscroll\" Cross-Site Scripting - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12312536&styleName=Text&projectId=12310272","name":"http://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12312536&styleName=Text&projectId=12310272","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Release Notes - ASF JIRA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/36377","name":"http://osvdb.org/36377","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/24480","name":"http://www.securityfocus.com/bid/24480","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Apache MyFaces Tomahawk JSF Framework Autoscroll Parameter Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34872","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34872","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2212","name":"http://www.vupen.com/english/advisories/2007/2212","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3101","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3101","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3101","vulnerable":"1","versionEndIncluding":"1.1.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"myfaces_tomahawk","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:05:28.673Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"25618","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25618"},{"name":"myfaces-autoscroll-xss(34872)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34872"},{"name":"20070614 Apache MyFaces Tomahawk JSF Framework Cross-Site Scripting (XSS) Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=544"},{"name":"36377","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36377"},{"name":"24480","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24480"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12312536&styleName=Text&projectId=12310272"},{"name":"ADV-2007-2212","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2212"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"25618","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25618"},{"name":"myfaces-autoscroll-xss(34872)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34872"},{"name":"20070614 Apache MyFaces Tomahawk JSF Framework Cross-Site Scripting (XSS) Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=544"},{"name":"36377","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36377"},{"name":"24480","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24480"},{"tags":["x_refsource_CONFIRM"],"url":"http://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12312536&styleName=Text&projectId=12310272"},{"name":"ADV-2007-2212","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2212"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2007-3101","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"25618","refsource":"SECUNIA","url":"http://secunia.com/advisories/25618"},{"name":"myfaces-autoscroll-xss(34872)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34872"},{"name":"20070614 Apache MyFaces Tomahawk JSF Framework Cross-Site Scripting (XSS) Vulnerability","refsource":"IDEFENSE","url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=544"},{"name":"36377","refsource":"OSVDB","url":"http://osvdb.org/36377"},{"name":"24480","refsource":"BID","url":"http://www.securityfocus.com/bid/24480"},{"name":"http://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12312536&styleName=Text&projectId=12310272","refsource":"CONFIRM","url":"http://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12312536&styleName=Text&projectId=12310272"},{"name":"ADV-2007-2212","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2212"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2007-3101","datePublished":"2007-06-18T10:00:00.000Z","dateReserved":"2007-06-07T00:00:00.000Z","dateUpdated":"2024-08-07T14:05:28.673Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-18 10:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:myfaces_tomahawk:*:*:*:*:*:*:*:*","versionEndIncluding":"1.1.5","matchCriteriaId":"8C4B73C7-356E-4F2C-BF01-4D19D15D8FDA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3101","Ordinal":"1","Title":"CVE-2007-3101","CVE":"CVE-2007-3101","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3101","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.","Type":"Description","Title":"CVE-2007-3101"},{"CveYear":"2007","CveId":"3101","Ordinal":"2","NoteData":"2007-06-18","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3101","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}