{"api_version":"1","generated_at":"2026-07-23T03:41:27+00:00","cve":"CVE-2007-3540","urls":{"html":"https://cve.report/CVE-2007-3540","api":"https://cve.report/api/cve/CVE-2007-3540.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3540","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3540"},"summary":{"title":"CVE-2007-3540","description":"Multiple cross-site scripting (XSS) vulnerabilities in search.asp in rwAuction Pro 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) show, (3) searchtype, (4) catid, and (5) searchtxt parameters, a different version and vectors than CVE-2005-4060.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-07-03 20:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/25849","name":"http://secunia.com/advisories/25849","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rwAuction Pro \"search.asp\" Cross-Site Scripting - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2368","name":"http://www.vupen.com/english/advisories/2007/2368","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels-team.blogspot.com/2007/06/rwauction-pro-xss-vuln.html","name":"http://pridels-team.blogspot.com/2007/06/rwauction-pro-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"-UNSECURED SYSTEMS-: rwAuction Pro XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/36347","name":"http://osvdb.org/36347","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/24668","name":"http://www.securityfocus.com/bid/24668","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RWAuction Pro Search.ASP Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3540","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3540","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3540","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rainworx","cpe5":"rwauction_pro","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:21:36.169Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"24668","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24668"},{"name":"25849","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25849"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels-team.blogspot.com/2007/06/rwauction-pro-xss-vuln.html"},{"name":"36347","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36347"},{"name":"ADV-2007-2368","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2368"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in search.asp in rwAuction Pro 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) show, (3) searchtype, (4) catid, and (5) searchtxt parameters, a different version and vectors than CVE-2005-4060."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-07-19T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"24668","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24668"},{"name":"25849","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25849"},{"tags":["x_refsource_MISC"],"url":"http://pridels-team.blogspot.com/2007/06/rwauction-pro-xss-vuln.html"},{"name":"36347","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36347"},{"name":"ADV-2007-2368","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2368"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3540","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in search.asp in rwAuction Pro 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) show, (3) searchtype, (4) catid, and (5) searchtxt parameters, a different version and vectors than CVE-2005-4060."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"24668","refsource":"BID","url":"http://www.securityfocus.com/bid/24668"},{"name":"25849","refsource":"SECUNIA","url":"http://secunia.com/advisories/25849"},{"name":"http://pridels-team.blogspot.com/2007/06/rwauction-pro-xss-vuln.html","refsource":"MISC","url":"http://pridels-team.blogspot.com/2007/06/rwauction-pro-xss-vuln.html"},{"name":"36347","refsource":"OSVDB","url":"http://osvdb.org/36347"},{"name":"ADV-2007-2368","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2368"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3540","datePublished":"2007-07-03T20:00:00.000Z","dateReserved":"2007-07-03T00:00:00.000Z","dateUpdated":"2024-08-07T14:21:36.169Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-03 20:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rainworx:rwauction_pro:5.0:*:*:*:*:*:*:*","matchCriteriaId":"09037A73-A76E-4BD4-AA1D-A420C30EB85A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3540","Ordinal":"1","Title":"CVE-2007-3540","CVE":"CVE-2007-3540","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3540","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in search.asp in rwAuction Pro 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) show, (3) searchtype, (4) catid, and (5) searchtxt parameters, a different version and vectors than CVE-2005-4060.","Type":"Description","Title":"CVE-2007-3540"},{"CveYear":"2007","CveId":"3540","Ordinal":"2","NoteData":"2007-07-03","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3540","Ordinal":"3","NoteData":"2007-07-19","Type":"Other","Title":"Modified"}]}}}