CVE-2007-6306

Multiple cross-site scripting (XSS) vulnerabilities in the image map feature in JFreeChart 1.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) chart name or (2) chart tool tip text; or the (3) href, (4) shape, or (5) coords attribute of a chart area.
References
Link Resource
http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/branches/jfreechart-1.0.8-security/NEWS?r1=679&r2=680 Patch
http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/trunk/source/org/jfree/chart/entity/ChartEntity.java?r1=662&r2=661&pathrev=662 Exploit
http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/trunk/source/org/jfree/chart/imagemap/ImageMapUtilities.java?r1=662&r2=661&pathrev=662 Exploit
http://osvdb.org/41843
http://osvdb.org/41844
http://osvdb.org/41845
http://rhn.redhat.com/errata/RHSA-2008-0630.html
http://secunia.com/advisories/27959 Vendor Advisory
http://secunia.com/advisories/31493
http://securityreason.com/securityalert/3430
http://www.rapid7.com/advisories/R7-0031.jsp
http://www.redhat.com/support/errata/RHSA-2008-0151.html
http://www.redhat.com/support/errata/RHSA-2008-0158.html
http://www.redhat.com/support/errata/RHSA-2008-0213.html
http://www.redhat.com/support/errata/RHSA-2008-0261.html
http://www.securityfocus.com/archive/1/484709/100/0/threaded
http://www.securityfocus.com/bid/26752
https://exchange.xforce.ibmcloud.com/vulnerabilities/38922
http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/branches/jfreechart-1.0.8-security/NEWS?r1=679&r2=680 Patch
http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/trunk/source/org/jfree/chart/entity/ChartEntity.java?r1=662&r2=661&pathrev=662 Exploit
http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/trunk/source/org/jfree/chart/imagemap/ImageMapUtilities.java?r1=662&r2=661&pathrev=662 Exploit
http://osvdb.org/41843
http://osvdb.org/41844
http://osvdb.org/41845
http://rhn.redhat.com/errata/RHSA-2008-0630.html
http://secunia.com/advisories/27959 Vendor Advisory
http://secunia.com/advisories/31493
http://securityreason.com/securityalert/3430
http://www.rapid7.com/advisories/R7-0031.jsp
http://www.redhat.com/support/errata/RHSA-2008-0151.html
http://www.redhat.com/support/errata/RHSA-2008-0158.html
http://www.redhat.com/support/errata/RHSA-2008-0213.html
http://www.redhat.com/support/errata/RHSA-2008-0261.html
http://www.securityfocus.com/archive/1/484709/100/0/threaded
http://www.securityfocus.com/bid/26752
https://exchange.xforce.ibmcloud.com/vulnerabilities/38922
Configurations

Configuration 1 (hide)

cpe:2.3:o:jfree:jfreechart:1.0.8:*:*:*:*:*:*:*

History

21 Nov 2024, 00:39

Type Values Removed Values Added
References () http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/branches/jfreechart-1.0.8-security/NEWS?r1=679&r2=680 - Patch () http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/branches/jfreechart-1.0.8-security/NEWS?r1=679&r2=680 - Patch
References () http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/trunk/source/org/jfree/chart/entity/ChartEntity.java?r1=662&r2=661&pathrev=662 - Exploit () http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/trunk/source/org/jfree/chart/entity/ChartEntity.java?r1=662&r2=661&pathrev=662 - Exploit
References () http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/trunk/source/org/jfree/chart/imagemap/ImageMapUtilities.java?r1=662&r2=661&pathrev=662 - Exploit () http://jfreechart.svn.sourceforge.net/viewvc/jfreechart/trunk/source/org/jfree/chart/imagemap/ImageMapUtilities.java?r1=662&r2=661&pathrev=662 - Exploit
References () http://osvdb.org/41843 - () http://osvdb.org/41843 -
References () http://osvdb.org/41844 - () http://osvdb.org/41844 -
References () http://osvdb.org/41845 - () http://osvdb.org/41845 -
References () http://rhn.redhat.com/errata/RHSA-2008-0630.html - () http://rhn.redhat.com/errata/RHSA-2008-0630.html -
References () http://secunia.com/advisories/27959 - Vendor Advisory () http://secunia.com/advisories/27959 - Vendor Advisory
References () http://secunia.com/advisories/31493 - () http://secunia.com/advisories/31493 -
References () http://securityreason.com/securityalert/3430 - () http://securityreason.com/securityalert/3430 -
References () http://www.rapid7.com/advisories/R7-0031.jsp - () http://www.rapid7.com/advisories/R7-0031.jsp -
References () http://www.redhat.com/support/errata/RHSA-2008-0151.html - () http://www.redhat.com/support/errata/RHSA-2008-0151.html -
References () http://www.redhat.com/support/errata/RHSA-2008-0158.html - () http://www.redhat.com/support/errata/RHSA-2008-0158.html -
References () http://www.redhat.com/support/errata/RHSA-2008-0213.html - () http://www.redhat.com/support/errata/RHSA-2008-0213.html -
References () http://www.redhat.com/support/errata/RHSA-2008-0261.html - () http://www.redhat.com/support/errata/RHSA-2008-0261.html -
References () http://www.securityfocus.com/archive/1/484709/100/0/threaded - () http://www.securityfocus.com/archive/1/484709/100/0/threaded -
References () http://www.securityfocus.com/bid/26752 - () http://www.securityfocus.com/bid/26752 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/38922 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/38922 -

Information

Published : 2007-12-11 21:46

Updated : 2024-11-21 00:39


NVD link : CVE-2007-6306

Mitre link : CVE-2007-6306

CVE.ORG link : CVE-2007-6306


JSON object : View

Products Affected

jfree

  • jfreechart
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')