5
CVSSv2

CVE-2007-2383

Published: 30/04/2007 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Prototype (prototypejs) framework prior to 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote malicious users to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

Vulnerable Product Search on Vulmon Subscribe to Product

prototypejs prototype framework 1.5.1_rc3

Vendor Advisories

Debian Bug report logs - #555217 auth2db: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities Package: auth2db; Maintainer for auth2db is Ulises Vitulli <dererk@debianorg>; Source for auth2db is src:auth2db (PTS, buildd, popcon) Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Mon, 9 Nov 200 ...

Github Repositories

repository for vulnerability check bootstrap: CVE-2018-14041 jQuery: CVE-2015-9251 prototypejs: CVE-2008-7220 and CVE-2007-2383 maybe GitHub can't detect prototypejs's vulnerabilities