Unrated severityNVD Advisory· Published Jun 30, 2007· Updated Apr 23, 2026
CVE-2007-2801
CVE-2007-2801
Description
Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) err and (2) warn parameters. NOTE: the vendor disputes the significance of the issue, stating that "eTicket is not designed to work with register_globals On."
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.securityfocus.com/bid/24681nvdExploit
- secunia.com/advisories/25871nvdVendor Advisory
- www.netvigilance.com/advisory0031nvdVendor Advisory
- www.vupen.com/english/advisories/2007/2372nvdVendor Advisory
- marc.infonvd
- www.osvdb.org/34786nvd
- www.securityfocus.com/archive/1/472434/100/0/threadednvd
- www.securityfocus.com/archive/1/472514/100/0/threadednvd
- www.securityfocus.com/archive/1/473095/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/35121nvd
News mentions
0No linked articles in our index yet.