CVE-2007-5985
BtiTracker <1.4.5 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php.
References (15)
Scores
EPSS
0.0076
EPSS Percentile
73.2%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
bti-tracker/bti-tracker
< 1.3.2
Timeline
Published
Nov 15, 2007
Tracked Since
Feb 18, 2026