{"api_version":"1","generated_at":"2026-07-23T11:06:03+00:00","cve":"CVE-2007-5577","urls":{"html":"https://cve.report/CVE-2007-5577","api":"https://cve.report/api/cve/CVE-2007-5577.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5577","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5577"},"summary":{"title":"CVE-2007-5577","description":"Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Name form fields in the Section Manager component, or (3) multiple unspecified fields in New Menu Item.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-18 21:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.joomla.org/content/view/3670/78/","name":"http://www.joomla.org/content/view/3670/78/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"],"title":"Joomla! - 1.0.13 Changelog","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/37173","name":"http://osvdb.org/37173","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/24663","name":"http://www.securityfocus.com/bid/24663","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Joomla! Administration Module Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&tracker_item_id=5654","name":"http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&tracker_item_id=5654","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Projects > Joomla! > Tracker > Joomla! 1.0.x Bug Tracker > Edit Tracker Item","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.joomla.org/content/view/3677/1/","name":"http://www.joomla.org/content/view/3677/1/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Joomla! - Joomla! 1.0.13 Released","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25804","name":"http://secunia.com/advisories/25804","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Joomla! Section Manager Script Insertion - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35119","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35119","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5577","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5577","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5577","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"joomla","cpe5":"joomla\\!","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:39:12.411Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.joomla.org/content/view/3677/1/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&tracker_item_id=5654"},{"name":"37173","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37173"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.joomla.org/content/view/3670/78/"},{"name":"25804","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25804"},{"name":"24663","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24663"},{"name":"joomla-section-manager-xss(35119)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35119"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Name form fields in the Section Manager component, or (3) multiple unspecified fields in New Menu Item."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.joomla.org/content/view/3677/1/"},{"tags":["x_refsource_CONFIRM"],"url":"http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&tracker_item_id=5654"},{"name":"37173","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37173"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.joomla.org/content/view/3670/78/"},{"name":"25804","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25804"},{"name":"24663","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24663"},{"name":"joomla-section-manager-xss(35119)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35119"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5577","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Name form fields in the Section Manager component, or (3) multiple unspecified fields in New Menu Item."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.joomla.org/content/view/3677/1/","refsource":"MISC","url":"http://www.joomla.org/content/view/3677/1/"},{"name":"http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&tracker_item_id=5654","refsource":"CONFIRM","url":"http://joomlacode.org/gf/project/joomla/tracker/?action=TrackerItemEdit&tracker_item_id=5654"},{"name":"37173","refsource":"OSVDB","url":"http://osvdb.org/37173"},{"name":"http://www.joomla.org/content/view/3670/78/","refsource":"CONFIRM","url":"http://www.joomla.org/content/view/3670/78/"},{"name":"25804","refsource":"SECUNIA","url":"http://secunia.com/advisories/25804"},{"name":"24663","refsource":"BID","url":"http://www.securityfocus.com/bid/24663"},{"name":"joomla-section-manager-xss(35119)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35119"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5577","datePublished":"2007-10-18T21:00:00.000Z","dateReserved":"2007-10-18T00:00:00.000Z","dateUpdated":"2024-08-07T15:39:12.411Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-18 21:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.13","matchCriteriaId":"3C3B9154-1305-4AB7-BFE8-FC0803370828"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5577","Ordinal":"1","Title":"CVE-2007-5577","CVE":"CVE-2007-5577","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5577","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Name form fields in the Section Manager component, or (3) multiple unspecified fields in New Menu Item.","Type":"Description","Title":"CVE-2007-5577"},{"CveYear":"2007","CveId":"5577","Ordinal":"2","NoteData":"2007-10-18","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5577","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}