CVE-2007-6726
Dojo 0.4.1-0.4.2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.
References (6)
Scores
EPSS
0.0175
EPSS Percentile
82.3%
Classification
CWE
CWE-79
Status
published
Affected Products (5)
apache/struts
dojotoolkit/dojo
dojotoolkit/dojo
org.apache.struts/struts2-dojo-plugin
< 0.4.3Maven
n/a/n/a
Timeline
Published
Apr 09, 2009
Tracked Since
Feb 18, 2026