CVE-2007-6726

Dojo 0.4.1-0.4.2 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.

Scores

EPSS 0.0175
EPSS Percentile 82.3%

Classification

CWE
CWE-79
Status published

Affected Products (5)

apache/struts
dojotoolkit/dojo
dojotoolkit/dojo
org.apache.struts/struts2-dojo-plugin < 0.4.3Maven
n/a/n/a

Timeline

Published Apr 09, 2009
Tracked Since Feb 18, 2026