{"api_version":"1","generated_at":"2026-07-23T05:02:41+00:00","cve":"CVE-2007-5932","urls":{"html":"https://cve.report/CVE-2007-5932","api":"https://cve.report/api/cve/CVE-2007-5932.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5932","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5932"},"summary":{"title":"CVE-2007-5932","description":"Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web script or HTML via unspecified form fields related to the (1) search function, (2) advanced search function, and possibly other components.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-11-10 11:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://osvdb.org/38704","name":"http://osvdb.org/38704","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38305","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38305","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/38703","name":"http://osvdb.org/38703","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/3910","name":"http://www.vupen.com/english/advisories/2007/3910","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.portcullis-security.com/223.php","name":"http://www.portcullis-security.com/223.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Portcullis -  \n\t\t\t\tThe CMS is vulnerable to XSS in multiple locations","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26472","name":"http://www.securityfocus.com/bid/26472","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"FatWire Content Server Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/27663","name":"http://secunia.com/advisories/27663","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"FatWire Content Server Two Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5932","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5932","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5932","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fatwire","cpe5":"fatwire_content_server","cpe6":"6.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:47:00.422Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"38704","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/38704"},{"name":"fatwire-search-xss(38305)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38305"},{"name":"27663","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27663"},{"name":"26472","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26472"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.portcullis-security.com/223.php"},{"name":"38703","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/38703"},{"name":"ADV-2007-3910","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3910"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-11-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web script or HTML via unspecified form fields related to the (1) search function, (2) advanced search function, and possibly other components."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"38704","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/38704"},{"name":"fatwire-search-xss(38305)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38305"},{"name":"27663","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27663"},{"name":"26472","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26472"},{"tags":["x_refsource_MISC"],"url":"http://www.portcullis-security.com/223.php"},{"name":"38703","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/38703"},{"name":"ADV-2007-3910","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3910"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5932","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web script or HTML via unspecified form fields related to the (1) search function, (2) advanced search function, and possibly other components."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"38704","refsource":"OSVDB","url":"http://osvdb.org/38704"},{"name":"fatwire-search-xss(38305)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38305"},{"name":"27663","refsource":"SECUNIA","url":"http://secunia.com/advisories/27663"},{"name":"26472","refsource":"BID","url":"http://www.securityfocus.com/bid/26472"},{"name":"http://www.portcullis-security.com/223.php","refsource":"MISC","url":"http://www.portcullis-security.com/223.php"},{"name":"38703","refsource":"OSVDB","url":"http://osvdb.org/38703"},{"name":"ADV-2007-3910","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3910"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5932","datePublished":"2007-11-10T11:00:00.000Z","dateReserved":"2007-11-09T00:00:00.000Z","dateUpdated":"2024-08-07T15:47:00.422Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-11-10 11:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fatwire:fatwire_content_server:6.3.0:*:*:*:*:*:*:*","matchCriteriaId":"1EB44EDE-B647-4920-9F1D-58C51D5111B9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5932","Ordinal":"1","Title":"CVE-2007-5932","CVE":"CVE-2007-5932","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5932","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web script or HTML via unspecified form fields related to the (1) search function, (2) advanced search function, and possibly other components.","Type":"Description","Title":"CVE-2007-5932"},{"CveYear":"2007","CveId":"5932","Ordinal":"2","NoteData":"2007-11-10","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5932","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}