CVE-2007-2380

Microsoft Atlas Framework - Information Disclosure via JSON Data Hijacking

Title source: llm
STIX 2.1

Description

The Microsoft Atlas framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/43325

Scores

EPSS 0.1230
EPSS Percentile 95.8%

Details

Status published
Products (1)
microsoft/atlas_framework
Published Apr 30, 2007
Tracked Since Feb 18, 2026