{"api_version":"1","generated_at":"2026-07-23T07:29:55+00:00","cve":"CVE-2007-5280","urls":{"html":"https://cve.report/CVE-2007-5280","api":"https://cve.report/api/cve/CVE-2007-5280.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5280","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5280"},"summary":{"title":"CVE-2007-5280","description":"Multiple cross-site scripting (XSS) vulnerabilities in messages.jsp in AppFuse before 2.0 Final allow remote attackers to inject arbitrary web script or HTML via unspecified input that is recorded in (1) success or (2) error messages.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-09 00:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/27041","name":"http://secunia.com/advisories/27041","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"AppFuse messages.jsp Cross-Site Scripting Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25927","name":"http://www.securityfocus.com/bid/25927","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"AppFuse Messages.JSP Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/37423","name":"http://osvdb.org/37423","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://issues.appfuse.org/browse/APF-880","name":"http://issues.appfuse.org/browse/APF-880","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[#APF-880] messages.jsp - cross site scripting - AppFuse JIRA","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://appfuse.org/display/APF/Release+Notes+2.0","name":"http://appfuse.org/display/APF/Release+Notes+2.0","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"500"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5280","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5280","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5280","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"appfuse","cpe5":"appfuse","cpe6":"2.0-rc1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:24:42.394Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://appfuse.org/display/APF/Release+Notes+2.0"},{"name":"27041","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27041"},{"name":"37423","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37423"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://issues.appfuse.org/browse/APF-880"},{"name":"25927","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25927"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in messages.jsp in AppFuse before 2.0 Final allow remote attackers to inject arbitrary web script or HTML via unspecified input that is recorded in (1) success or (2) error messages."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-11-15T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://appfuse.org/display/APF/Release+Notes+2.0"},{"name":"27041","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27041"},{"name":"37423","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37423"},{"tags":["x_refsource_CONFIRM"],"url":"http://issues.appfuse.org/browse/APF-880"},{"name":"25927","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25927"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5280","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in messages.jsp in AppFuse before 2.0 Final allow remote attackers to inject arbitrary web script or HTML via unspecified input that is recorded in (1) success or (2) error messages."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://appfuse.org/display/APF/Release+Notes+2.0","refsource":"CONFIRM","url":"http://appfuse.org/display/APF/Release+Notes+2.0"},{"name":"27041","refsource":"SECUNIA","url":"http://secunia.com/advisories/27041"},{"name":"37423","refsource":"OSVDB","url":"http://osvdb.org/37423"},{"name":"http://issues.appfuse.org/browse/APF-880","refsource":"CONFIRM","url":"http://issues.appfuse.org/browse/APF-880"},{"name":"25927","refsource":"BID","url":"http://www.securityfocus.com/bid/25927"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5280","datePublished":"2007-10-09T00:00:00.000Z","dateReserved":"2007-10-08T00:00:00.000Z","dateUpdated":"2024-08-07T15:24:42.394Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-09 00:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:appfuse:appfuse:2.0-rc1:*:*:*:*:*:*:*","matchCriteriaId":"7A5F2F67-8CB1-4588-AB9B-1F4F131D6F29"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5280","Ordinal":"1","Title":"CVE-2007-5280","CVE":"CVE-2007-5280","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5280","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in messages.jsp in AppFuse before 2.0 Final allow remote attackers to inject arbitrary web script or HTML via unspecified input that is recorded in (1) success or (2) error messages.","Type":"Description","Title":"CVE-2007-5280"},{"CveYear":"2007","CveId":"5280","Ordinal":"2","NoteData":"2007-10-08","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5280","Ordinal":"3","NoteData":"2008-11-15","Type":"Other","Title":"Modified"}]}}}