CVE-2007-5985

BtiTracker <1.4.5 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php.

Scores

EPSS 0.0076
EPSS Percentile 73.2%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

bti-tracker/bti-tracker < 1.3.2

Timeline

Published Nov 15, 2007
Tracked Since Feb 18, 2026