CVE-2007-2381 describes a JavaScript Hijacking vulnerability in the MochiKit framework, specifically affecting mochikit and mochikit_framework. The vulnerability arises because MochiKit exchanges JSON data without adequate protection, allowing remote attackers to retrieve sensitive information. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N), this medium-severity flaw indicates that an unauthenticated attacker could achieve partial confidentiality impact with low attack complexity over a network. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not a widely targeted or discussed vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:mochikit:mochikit_framework:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.