{"api_version":"1","generated_at":"2026-07-23T07:36:53+00:00","cve":"CVE-2007-5796","urls":{"html":"https://cve.report/CVE-2007-5796","api":"https://cve.report/api/cve/CVE-2007-5796.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5796","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5796"},"summary":{"title":"CVE-2007-5796","description":"Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate Revocation Lists.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-11-03 00:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id?1018888","name":"http://www.securitytracker.com/id?1018888","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Blue Coat ProxySG Management Console Input Validation Hole in Processing CRLs Permits Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.bluecoat.com/support/securityadvisories/advisory_cross-site_scripting_vulnerability","name":"http://www.bluecoat.com/support/securityadvisories/advisory_cross-site_scripting_vulnerability","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Security Advisories | Blue Coat Systems, Inc.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38213","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38213","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27452","name":"http://secunia.com/advisories/27452","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Blue Coat ProxySG SGOS Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3678","name":"http://www.vupen.com/english/advisories/2007/3678","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5796","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5796","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5796","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"symantec","cpe5":"proxysg_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:47:00.644Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.bluecoat.com/support/securityadvisories/advisory_cross-site_scripting_vulnerability"},{"name":"proxysg-management-console-xss(38213)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38213"},{"name":"27452","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27452"},{"name":"ADV-2007-3678","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3678"},{"name":"1018888","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018888"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate Revocation Lists."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.bluecoat.com/support/securityadvisories/advisory_cross-site_scripting_vulnerability"},{"name":"proxysg-management-console-xss(38213)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38213"},{"name":"27452","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27452"},{"name":"ADV-2007-3678","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3678"},{"name":"1018888","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018888"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5796","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate Revocation Lists."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.bluecoat.com/support/securityadvisories/advisory_cross-site_scripting_vulnerability","refsource":"CONFIRM","url":"http://www.bluecoat.com/support/securityadvisories/advisory_cross-site_scripting_vulnerability"},{"name":"proxysg-management-console-xss(38213)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38213"},{"name":"27452","refsource":"SECUNIA","url":"http://secunia.com/advisories/27452"},{"name":"ADV-2007-3678","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3678"},{"name":"1018888","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018888"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5796","datePublished":"2007-11-03T00:00:00.000Z","dateReserved":"2007-11-02T00:00:00.000Z","dateUpdated":"2024-08-07T15:47:00.644Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-11-03 00:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:symantec:proxysg_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"4.2.6.1","matchCriteriaId":"27934E07-8F55-443F-AF3D-C562A437A99E"},{"vulnerable":true,"criteria":"cpe:2.3:o:symantec:proxysg_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.2.2.5","matchCriteriaId":"7723A628-CAF2-4D7A-9BCD-AE95EE36D860"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:symantec:proxysg:-:*:*:*:*:*:*:*","matchCriteriaId":"7660647E-FDD2-40AE-945A-FB3FE30AC4E6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5796","Ordinal":"1","Title":"CVE-2007-5796","CVE":"CVE-2007-5796","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5796","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate Revocation Lists.","Type":"Description","Title":"CVE-2007-5796"},{"CveYear":"2007","CveId":"5796","Ordinal":"2","NoteData":"2007-11-02","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5796","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}