CVE-2007-5113 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3% (pctl 87)
Patch early
A public exploit exists.
Description
report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 2.98% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-09-26 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| roi revolution | urchin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Google Urchin 5.7.3 - 'Report.cgi' Authentication Bypass | 2007-10-11 |
References
- http://ha.ckers.org/blog/20070823/xss-and-possible-information-disclosure-in-urchin/
- http://securityvulns.ru/Sdocument90.html
- http://websecurity.com.ua/1283/
- http://www.securityfocus.com/archive/1/482006/100/0/threaded
- http://www.securityfocus.com/bid/26037
- http://ha.ckers.org/blog/20070823/xss-and-possible-information-disclosure-in-urchin/
- http://securityvulns.ru/Sdocument90.html
- http://websecurity.com.ua/1283/
- http://www.securityfocus.com/archive/1/482006/100/0/threaded
- http://www.securityfocus.com/bid/26037
→ the Explorer · watch your stack · NVD