CVE-2007-5954

MEDIUM

JLMForo System - Cross-Site Scripting via buscador.php clave Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-5954. PoCs published by Jose Luis Gongora Fernandez.

AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in JLMForo System, where the 'clave' parameter in 'buscador.php' is not properly sanitized. An attacker can exploit this by injecting arbitrary script code into the URL parameter.

Description

Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo System allows remote attackers to inject arbitrary web script or HTML via the clave parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Jose Luis Gongora Fernandez · textwebappsphp
https://www.exploit-db.com/exploits/30739

The provided text describes a cross-site scripting (XSS) vulnerability in JLMForo System, where the 'clave' parameter in 'buscador.php' is not properly sanitized. An attacker can exploit this by injecting arbitrary script code into the URL parameter.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: JLMForo System
No auth needed
Prerequisites: Access to the vulnerable 'buscador.php' endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26331

Scores

CVSS v3 6.1
EPSS 0.0102
EPSS Percentile 59.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
jlmforo_system/jlmforo_system
Published Nov 14, 2007
Tracked Since Feb 18, 2026