{"api_version":"1","generated_at":"2026-07-23T09:35:58+00:00","cve":"CVE-2007-6001","urls":{"html":"https://cve.report/CVE-2007-6001","api":"https://cve.report/api/cve/CVE-2007-6001.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-6001","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-6001"},"summary":{"title":"CVE-2007-6001","description":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) func or (2) date parameter, or the jid parameter in a (3) log or (4) user action, a different vulnerability than CVE-2007-3910.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-11-15 22:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.portcullis-security.com/180.php","name":"http://www.portcullis-security.com/180.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Portcullis -  \n\t\t\t\tThe parameters are vulnerable to Javascript injection","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26553","name":"http://www.securityfocus.com/bid/26553","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bandersnatch Index.PHP Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38360","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38360","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-6001","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-6001","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"6001","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bandersnatch","cpe5":"bandersnatch","cpe6":"0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:47:00.705Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"bandersnatch-index-xss(38360)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38360"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.portcullis-security.com/180.php"},{"name":"26553","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26553"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-11-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) func or (2) date parameter, or the jid parameter in a (3) log or (4) user action, a different vulnerability than CVE-2007-3910."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"bandersnatch-index-xss(38360)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38360"},{"tags":["x_refsource_MISC"],"url":"http://www.portcullis-security.com/180.php"},{"name":"26553","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26553"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-6001","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) func or (2) date parameter, or the jid parameter in a (3) log or (4) user action, a different vulnerability than CVE-2007-3910."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"bandersnatch-index-xss(38360)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38360"},{"name":"http://www.portcullis-security.com/180.php","refsource":"MISC","url":"http://www.portcullis-security.com/180.php"},{"name":"26553","refsource":"BID","url":"http://www.securityfocus.com/bid/26553"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-6001","datePublished":"2007-11-15T22:00:00.000Z","dateReserved":"2007-11-15T00:00:00.000Z","dateUpdated":"2024-08-07T15:47:00.705Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-11-15 22:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bandersnatch:bandersnatch:0.4:*:*:*:*:*:*:*","matchCriteriaId":"45F3F222-97C9-41BE-93A5-D2DE872B64B4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"6001","Ordinal":"1","Title":"CVE-2007-6001","CVE":"CVE-2007-6001","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"6001","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) func or (2) date parameter, or the jid parameter in a (3) log or (4) user action, a different vulnerability than CVE-2007-3910.","Type":"Description","Title":"CVE-2007-6001"},{"CveYear":"2007","CveId":"6001","Ordinal":"2","NoteData":"2007-11-15","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"6001","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}