{"api_version":"1","generated_at":"2026-07-23T12:02:27+00:00","cve":"CVE-2007-5480","urls":{"html":"https://cve.report/CVE-2007-5480","api":"https://cve.report/api/cve/CVE-2007-5480.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5480","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5480"},"summary":{"title":"CVE-2007-5480","description":"Multiple cross-site scripting (XSS) vulnerabilities in InnovaAge InnovaShop allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to msg.jsp, and the (2) contentid parameter to tc/contents/home001.jsp.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-16 23:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/26084","name":"http://www.securityfocus.com/bid/26084","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"InnovaShop Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37273","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37273","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/37927","name":"http://osvdb.org/37927","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/37928","name":"http://osvdb.org/37928","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/27225","name":"http://secunia.com/advisories/27225","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"InnovaPortal Multiple Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=119248056804520&w=2","name":"http://marc.info/?l=bugtraq&m=119248056804520&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5480","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5480","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"innovaage","cpe5":"innovashop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:31:58.862Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20071015 InnovaShop?® (mgs.jps) Cross Siting Scripting","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=119248056804520&w=2"},{"name":"37927","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37927"},{"name":"27225","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27225"},{"name":"innovashop-msg-home001-xss(37273)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37273"},{"name":"37928","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37928"},{"name":"26084","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26084"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in InnovaAge InnovaShop allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to msg.jsp, and the (2) contentid parameter to tc/contents/home001.jsp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20071015 InnovaShop?® (mgs.jps) Cross Siting Scripting","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=119248056804520&w=2"},{"name":"37927","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37927"},{"name":"27225","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27225"},{"name":"innovashop-msg-home001-xss(37273)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37273"},{"name":"37928","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37928"},{"name":"26084","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26084"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5480","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in InnovaAge InnovaShop allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to msg.jsp, and the (2) contentid parameter to tc/contents/home001.jsp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20071015 InnovaShop?® (mgs.jps) Cross Siting Scripting","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=119248056804520&w=2"},{"name":"37927","refsource":"OSVDB","url":"http://osvdb.org/37927"},{"name":"27225","refsource":"SECUNIA","url":"http://secunia.com/advisories/27225"},{"name":"innovashop-msg-home001-xss(37273)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37273"},{"name":"37928","refsource":"OSVDB","url":"http://osvdb.org/37928"},{"name":"26084","refsource":"BID","url":"http://www.securityfocus.com/bid/26084"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5480","datePublished":"2007-10-16T23:00:00.000Z","dateReserved":"2007-10-16T00:00:00.000Z","dateUpdated":"2024-08-07T15:31:58.862Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-16 23:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:innovaage:innovashop:*:*:*:*:*:*:*:*","matchCriteriaId":"78A85A5F-5FA8-4811-937F-652DAE48BB05"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5480","Ordinal":"1","Title":"CVE-2007-5480","CVE":"CVE-2007-5480","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5480","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in InnovaAge InnovaShop allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to msg.jsp, and the (2) contentid parameter to tc/contents/home001.jsp.","Type":"Description","Title":"CVE-2007-5480"},{"CveYear":"2007","CveId":"5480","Ordinal":"2","NoteData":"2007-10-16","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5480","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}