{"api_version":"1","generated_at":"2026-07-23T04:30:16+00:00","cve":"CVE-2007-6560","urls":{"html":"https://cve.report/CVE-2007-6560","api":"https://cve.report/api/cve/CVE-2007-6560.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-6560","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-6560"},"summary":{"title":"CVE-2007-6560","description":"Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-12-28 00:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/490101/100/0/threaded","name":"http://www.securityfocus.com/archive/1/490101/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27003","name":"http://www.securityfocus.com/bid/27003","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Logaholic Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/485480/100/0/threaded","name":"http://www.securityfocus.com/archive/1/485480/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/3496","name":"http://securityreason.com/securityalert/3496","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - Logaholic Web Analytics Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/39792","name":"http://osvdb.org/39792","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/39793","name":"http://osvdb.org/39793","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/28263","name":"http://secunia.com/advisories/28263","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Logaholic Cross-Site Scripting and SQL Injection - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39223","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39223","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-6560","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-6560","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"6560","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"logaholic","cpe5":"logaholic","cpe6":"0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:11:06.018Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"39793","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/39793"},{"name":"28263","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28263"},{"name":"3496","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3496"},{"name":"logaholic-profiles-xss(39223)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39223"},{"name":"39792","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/39792"},{"name":"27003","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27003"},{"name":"20071223 Logaholic Web Analytics Software","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/485480/100/0/threaded"},{"name":"20080326 Re: Logaholic Web Analytics Software","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/490101/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-12-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"39793","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/39793"},{"name":"28263","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28263"},{"name":"3496","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3496"},{"name":"logaholic-profiles-xss(39223)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39223"},{"name":"39792","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/39792"},{"name":"27003","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27003"},{"name":"20071223 Logaholic Web Analytics Software","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/485480/100/0/threaded"},{"name":"20080326 Re: Logaholic Web Analytics Software","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/490101/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-6560","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"39793","refsource":"OSVDB","url":"http://osvdb.org/39793"},{"name":"28263","refsource":"SECUNIA","url":"http://secunia.com/advisories/28263"},{"name":"3496","refsource":"SREASON","url":"http://securityreason.com/securityalert/3496"},{"name":"logaholic-profiles-xss(39223)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39223"},{"name":"39792","refsource":"OSVDB","url":"http://osvdb.org/39792"},{"name":"27003","refsource":"BID","url":"http://www.securityfocus.com/bid/27003"},{"name":"20071223 Logaholic Web Analytics Software","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/485480/100/0/threaded"},{"name":"20080326 Re: Logaholic Web Analytics Software","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/490101/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-6560","datePublished":"2007-12-28T00:00:00.000Z","dateReserved":"2007-12-27T00:00:00.000Z","dateUpdated":"2024-08-07T16:11:06.018Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-12-28 00:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:logaholic:logaholic:0:*:*:*:*:*:*:*","matchCriteriaId":"B1B96490-D3B6-4E1E-92CD-A7B2279929C8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"6560","Ordinal":"1","Title":"CVE-2007-6560","CVE":"CVE-2007-6560","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"6560","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.","Type":"Description","Title":"CVE-2007-6560"},{"CveYear":"2007","CveId":"6560","Ordinal":"2","NoteData":"2007-12-27","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"6560","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}