// For flags

CVE-2007-2383

Debian Linux Security Advisory 1952-1

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

El framework Prototype (prototypejs) versiones anteriores a 1.5.1 RC3, intercambia datos usando JavaScript Object Notation (JSON) sin un esquema de protección asociado, lo que permite a atacantes remotos obtener los datos por medio de una página web que recupera los datos por medio de una URL en el atributo SRC de un elemento SCRIPT y captura los datos usando otro código JavaScript, también se conoce como "JavaScript Hijacking".

Several vulnerabilities have been discovered in asterisk, an Open Source PBX and telephony toolkit.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-04-30 CVE Reserved
  • 2007-04-30 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-06-15 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Prototypejs
Search vendor "Prototypejs"
Prototype Framework
Search vendor "Prototypejs" for product "Prototype Framework"
1.5.1_rc3
Search vendor "Prototypejs" for product "Prototype Framework" and version "1.5.1_rc3"
-
Affected