{"api_version":"1","generated_at":"2026-07-23T04:58:34+00:00","cve":"CVE-2007-4587","urls":{"html":"https://cve.report/CVE-2007-4587","api":"https://cve.report/api/cve/CVE-2007-4587.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4587","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4587"},"summary":{"title":"CVE-2007-4587","description":"Cross-site scripting (XSS) vulnerability in Easy Software Cafeteria escafeWeb (aka Tuigwaa) 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the setting of option.nopage.create in tuigwaa.properties.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-08-29 01:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://osvdb.org/37147","name":"http://osvdb.org/37147","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36264","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36264","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26577","name":"http://secunia.com/advisories/26577","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"escafeWeb (Tuigwaa) Cross-Site Scripting Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/jp/JVN%2382276964/index.html","name":"http://jvn.jp/jp/JVN%2382276964/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#82276964: Tuigwaa におけるクロスサイトスクリプティングの脆弱性","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/25447","name":"http://www.securityfocus.com/bid/25447","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"Tuigwaa Unspecified Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.escafe.org/main/Security","name":"http://www.escafe.org/main/Security","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"escafe.org - Webアプリケーションを手軽に作れる便利なソフトウェア「escafe（エスカフェ）」","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/jp/JVN#82276964/index.html","name":"JVN:JVN#82276964","refsource":"MITRE","tags":[],"title":"","mime":"text/plain","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4587","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4587","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4587","vulnerable":"1","versionEndIncluding":"1.0.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_seasar_foundation","cpe5":"escafeweb","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:01:09.863Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"escafeweb-unspecified-xss(36264)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36264"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.escafe.org/main/Security"},{"name":"37147","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37147"},{"name":"26577","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26577"},{"name":"JVN#82276964","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/jp/JVN%2382276964/index.html"},{"name":"25447","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25447"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Easy Software Cafeteria escafeWeb (aka Tuigwaa) 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the setting of option.nopage.create in tuigwaa.properties."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"escafeweb-unspecified-xss(36264)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36264"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.escafe.org/main/Security"},{"name":"37147","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37147"},{"name":"26577","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26577"},{"name":"JVN#82276964","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/jp/JVN%2382276964/index.html"},{"name":"25447","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25447"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4587","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Easy Software Cafeteria escafeWeb (aka Tuigwaa) 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the setting of option.nopage.create in tuigwaa.properties."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"escafeweb-unspecified-xss(36264)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36264"},{"name":"http://www.escafe.org/main/Security","refsource":"CONFIRM","url":"http://www.escafe.org/main/Security"},{"name":"37147","refsource":"OSVDB","url":"http://osvdb.org/37147"},{"name":"26577","refsource":"SECUNIA","url":"http://secunia.com/advisories/26577"},{"name":"JVN#82276964","refsource":"JVN","url":"http://jvn.jp/jp/JVN%2382276964/index.html"},{"name":"25447","refsource":"BID","url":"http://www.securityfocus.com/bid/25447"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4587","datePublished":"2007-08-29T01:00:00.000Z","dateReserved":"2007-08-28T00:00:00.000Z","dateUpdated":"2024-08-07T15:01:09.863Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-08-29 01:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:the_seasar_foundation:escafeweb:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.4","matchCriteriaId":"430F5193-CB0F-4E29-9E05-3A8999E3D488"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4587","Ordinal":"1","Title":"CVE-2007-4587","CVE":"CVE-2007-4587","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4587","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Easy Software Cafeteria escafeWeb (aka Tuigwaa) 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the setting of option.nopage.create in tuigwaa.properties.","Type":"Description","Title":"CVE-2007-4587"},{"CveYear":"2007","CveId":"4587","Ordinal":"2","NoteData":"2007-08-28","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4587","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}