VYPR
Unrated severityNVD Advisory· Published Nov 15, 2007· Updated Apr 23, 2026

CVE-2007-5982

CVE-2007-5982

Description

Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) room parameter to sources/frame.php, the (2) theme_c parameter to help/index.php, or the (3) INSTALL_X7CHATVERSION parameter to upgradev1.php.

Affected products

2
  • X7 Group/X7 Chat2 versions
    cpe:2.3:a:x7_group:x7_chat:2.0.4:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:x7_group:x7_chat:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:x7_group:x7_chat:2.0.5:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.