5
CVSSv2

CVE-2007-2385

Published: 30/04/2007 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote malicious users to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

Vulnerable Product Search on Vulmon Subscribe to Product

yahoo ui library

Vendor Advisories

Debian Bug report logs - #557745 yui: CVE-2007-2385 javascript hijacking Package: yui; Maintainer for yui is (unknown); Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Tue, 24 Nov 2009 03:12:05 UTC Severity: minor Tags: security Found in version 270b-1 Fixed in version 290dfsg01-01+rm Done: Debia ...