{"api_version":"1","generated_at":"2026-07-23T08:43:58+00:00","cve":"CVE-2007-4297","urls":{"html":"https://cve.report/CVE-2007-4297","api":"https://cve.report/api/cve/CVE-2007-4297.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4297","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4297"},"summary":{"title":"CVE-2007-4297","description":"Multiple cross-site scripting (XSS) vulnerabilities in yorumkaydet.asp in Dersimiz Haber Ekleme Modulu allow remote attackers to inject arbitrary web script or HTML via the (1) yazan, (2) mail, and (3) yorum parameters.  NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-08-10 20:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/2831","name":"http://www.vupen.com/english/advisories/2007/2831","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35911","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35911","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/37537","name":"http://osvdb.org/37537","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/25250","name":"http://www.securityfocus.com/bid/25250","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Dersimiz Haber Ekleme Modulu Yorumkaydet.ASP Multiple HTML Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.packetstormsecurity.org/0708-exploits/dersimiz-xss.txt","name":"http://www.packetstormsecurity.org/0708-exploits/dersimiz-xss.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Files ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26380","name":"http://secunia.com/advisories/26380","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Dersimiz Haber Ekleme Modulu yorumkaydet.asp Script Insertion - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4297","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4297","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4297","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aspindir","cpe5":"dersimiz_haber_ekleme_modulu","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:53:54.865Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"26380","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26380"},{"name":"25250","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25250"},{"name":"37537","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37537"},{"name":"ADV-2007-2831","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2831"},{"name":"dersimiz-yorumkaydet-xss(35911)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35911"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.packetstormsecurity.org/0708-exploits/dersimiz-xss.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in yorumkaydet.asp in Dersimiz Haber Ekleme Modulu allow remote attackers to inject arbitrary web script or HTML via the (1) yazan, (2) mail, and (3) yorum parameters.  NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"26380","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26380"},{"name":"25250","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25250"},{"name":"37537","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37537"},{"name":"ADV-2007-2831","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2831"},{"name":"dersimiz-yorumkaydet-xss(35911)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35911"},{"tags":["x_refsource_MISC"],"url":"http://www.packetstormsecurity.org/0708-exploits/dersimiz-xss.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4297","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in yorumkaydet.asp in Dersimiz Haber Ekleme Modulu allow remote attackers to inject arbitrary web script or HTML via the (1) yazan, (2) mail, and (3) yorum parameters.  NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"26380","refsource":"SECUNIA","url":"http://secunia.com/advisories/26380"},{"name":"25250","refsource":"BID","url":"http://www.securityfocus.com/bid/25250"},{"name":"37537","refsource":"OSVDB","url":"http://osvdb.org/37537"},{"name":"ADV-2007-2831","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2831"},{"name":"dersimiz-yorumkaydet-xss(35911)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35911"},{"name":"http://www.packetstormsecurity.org/0708-exploits/dersimiz-xss.txt","refsource":"MISC","url":"http://www.packetstormsecurity.org/0708-exploits/dersimiz-xss.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4297","datePublished":"2007-08-10T20:00:00.000Z","dateReserved":"2007-08-10T00:00:00.000Z","dateUpdated":"2024-08-07T14:53:54.865Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-08-10 20:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aspindir:dersimiz_haber_ekleme_modulu:*:*:*:*:*:*:*:*","matchCriteriaId":"B9D589FF-8756-4B66-9495-2E9074741B25"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4297","Ordinal":"1","Title":"CVE-2007-4297","CVE":"CVE-2007-4297","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4297","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in yorumkaydet.asp in Dersimiz Haber Ekleme Modulu allow remote attackers to inject arbitrary web script or HTML via the (1) yazan, (2) mail, and (3) yorum parameters.  NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2007-4297"},{"CveYear":"2007","CveId":"4297","Ordinal":"2","NoteData":"2007-08-10","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4297","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}