CVE detail
CVE-2007-2684 — CVE-2007-2684
Published 2007-05-21 · Modified 2026-06-16 · Vendor jetbox · Product jetbox_cms · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0161
EPSS probability
exploitation probability, 30d
74.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Jetbox CMS 2.1 allows remote attackers to obtain sensitive information via (1) a direct request to (a) main_page.php, (b) open_tree.php, and (c) outputs.php; (2) a malformed view parameter to index.php, as demonstrated with an SQL injection manipulation; or (3) the id[] parameter to admin/cms/opentree.php, which reveals the installation path in the resulting error message.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References