CVE-2007-2380
Microsoft Atlas Framework - Information Disclosure via JSON Data Hijacking
Title source: llmDescription
The Microsoft Atlas framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."
References (2)
Core 2
Core References
URL Repurposed x_refsource_misc
http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/43325
Scores
EPSS
0.1230
EPSS Percentile
95.8%
Details
Status
published
Products (1)
microsoft/atlas_framework
Published
Apr 30, 2007
Tracked Since
Feb 18, 2026