187 lines
6.4 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2009-1938",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-06-05T18:30:00.217",
"lastModified": "2017-08-17T01:30:34.803",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to database output and the frontend administrative panel."
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Joomla! v.1.5.x hasta la v1.5.10. Permite a usuarios remotos inyectar codigo de script web o c\u00f3digo HTML a trav\u00e9s de vectores de ataque no especificados relacionados con la salida de la base de datos y el panel de administraci\u00f3n de \"frontend\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5:*:*:*:*:*:*:*",
"matchCriteriaId": "2017D307-89B3-4D94-A266-C7D8D45960A6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5:rc1:*:*:*:*:*:*",
"matchCriteriaId": "302D47E2-CFA8-438C-82DB-335319454448"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5:rc2:*:*:*:*:*:*",
"matchCriteriaId": "94B01AD8-2B71-4A6A-8932-E61B0FE54246"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5:rc3:*:*:*:*:*:*",
"matchCriteriaId": "1058A361-4B10-4D7C-B789-64A38FE7E201"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.0:beta:*:*:*:*:*:*",
"matchCriteriaId": "D548B3C9-483F-492C-A6BB-694B7217FEE8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.0:beta1:*:*:*:*:*:*",
"matchCriteriaId": "9813E813-2983-4471-9E56-6F254810A66B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.0:beta2:*:*:*:*:*:*",
"matchCriteriaId": "A4F4F9E7-BA44-4235-A246-DB6C432C3873"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "495BD724-45BE-4214-B120-3A83BD9AD11B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.1:*:*:*:*:*:*:*",
"matchCriteriaId": "8CCDBF4D-A797-4828-A084-8C775FA94BDF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.2:*:*:*:*:*:*:*",
"matchCriteriaId": "BB1B7CF2-B717-4F37-A923-0E188FF3C47F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.3:*:*:*:*:*:*:*",
"matchCriteriaId": "CBA35EF1-1F8C-4AEA-89A0-3C1DD2DFBFE8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.4:*:*:*:*:*:*:*",
"matchCriteriaId": "3333C204-A022-4B53-B61F-3C5601F21FC0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.5:*:*:*:*:*:*:*",
"matchCriteriaId": "F2752717-AA95-4398-8091-24FD5925C4F7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.6:*:*:*:*:*:*:*",
"matchCriteriaId": "F7B3B3FB-E67D-4D9A-BE01-855FA2545772"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.7:*:*:*:*:*:*:*",
"matchCriteriaId": "B29D3E39-7B43-4D19-B39F-2EB56E30F737"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.8:*:*:*:*:*:*:*",
"matchCriteriaId": "5F155C3B-AAF5-4393-A964-E655113D84DE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.9:*:*:*:*:*:*:*",
"matchCriteriaId": "D1DA8EEE-F091-49D0-9F9D-4C83574B6A36"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.5.10:*:*:*:*:*:*:*",
"matchCriteriaId": "731CC868-70FC-44A0-8CC2-D0A4AC5CE094"
}
]
}
]
}
],
"references": [
{
"url": "http://developer.joomla.org/security/news/297-20090602-core-frontend-xss.html",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.joomla.org/announcements/release-news/5235-joomla-1511-security-release-now-available.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/35189",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2009/1497",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50923",
"source": "cve@mitre.org"
}
]
}