CVE-2007-3838

TBDev.NET DR 11-10-05-BETA-SF1:111005 - Cross-Site Scripting via Avatar Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3838. PoCs published by PescaoDeth.

AI-analyzed exploit summary This is a writeup describing an HTML injection vulnerability in TBDev.NET DR. The vulnerability allows an attacker to inject malicious JavaScript code via the 'avatar' POST parameter, leading to potential cookie theft or other client-side attacks.

Description

Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by PescaoDeth · textwebappsasp
https://www.exploit-db.com/exploits/30313

This is a writeup describing an HTML injection vulnerability in TBDev.NET DR. The vulnerability allows an attacker to inject malicious JavaScript code via the 'avatar' POST parameter, leading to potential cookie theft or other client-side attacks.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: TBDev.NET DR 010306 and prior versions
No auth needed
Prerequisites: Access to the target application's user profile page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26120
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24923

Scores

EPSS 0.0283
EPSS Percentile 86.4%

Details

Status published
Products (3)
tbdev.net/dr 11-10-05-beta-sf1_1
tbdev.net/dr 16-12-05-beta-1_161
tbdev.net/dr 010306
Published Jul 17, 2007
Tracked Since Feb 18, 2026