peter bassill · operator
$ cve CVE-2007-3101 JSON

CVE-2007-3101 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 44.5% (pctl 99)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS44.45% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2007-06-18
Last modified2026-06-16

Affected (1)

VendorProduct
apachemyfaces tomahawk

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD