129 lines
3.5 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2007-6002",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-11-15T22:46:00.000",
"lastModified": "2017-07-29T01:33:59.147",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in Fenriru (1) Sleipnir 2.5.17 R2 and earlier and (2) Grani 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field in a search for additions to the Favorites section."
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Fenriru (1) Sleipnir 2.5.17 R2 y anteriores y (2) Grani 3.0 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n mediante el campo Search en una busca de a\u00f1adidos en la secci\u00f3n Favorites."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:fenrir:grani:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.0",
"matchCriteriaId": "EE7D5963-DAC7-4DC3-893C-C27E724137D7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:fenrir:sleipnir:*:r2:*:*:*:*:*:*",
"versionEndIncluding": "2.5.17",
"matchCriteriaId": "3CB5998C-FBF9-4ABD-AF46-170385EA5AB1"
}
]
}
]
}
],
"references": [
{
"url": "http://jvn.jp/jp/JVN%2365427327/index.html",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/38875",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/38876",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/27655",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/27675",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
2023-04-24 12:24:31 +02:00
{
"url": "http://www.fenrir.co.jp/grani/note.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.fenrir.co.jp/sleipnir/note.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/26418",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38441",
"source": "cve@mitre.org"
}
]
}