peter bassill · operator
$ cve CVE-2007-5113 JSON

CVE-2007-5113 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.98% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2007-09-26
Last modified2026-06-16

Affected (1)

VendorProduct
roi revolutionurchin

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD