2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2008-6346" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2009-02-27T17:30:09.843" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T00:56:18.343" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Cross-site scripting (XSS) vulnerability in the DR Wiki (dr_wiki) extension 1.7.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de ejecuci\u00f3n de secuencias de comandos en sitios cruzados en la extensi\u00f3n Dr Wiki (dr_wiki) v1.7.1 y anteriores para TYPO3, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n a trav\u00e9s de vectores no determinados."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:N/I:P/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 4.3 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "PARTIAL" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "1.7.1" ,
"matchCriteriaId" : "87CCD79B-CD50-49AA-9F30-D2F6831FCC38"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "816996E9-858D-4AEB-B7EF-B816969AB31B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1DCB930E-7BFA-4034-9CD3-81DFE247B8F8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.5.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1F438694-740A-4FF0-9231-59982004281C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.5.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "106B30CE-3C1C-4493-B163-4533F74E907A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BA1CA68C-E2EB-46BF-9565-B36DF3B28363"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.6.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0B103A95-4D6B-4D71-B5D6-135C142762E0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.6.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "665B4C21-91C0-4677-948D-B92B91D2DE25"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D0A2003A-F871-4214-9C19-0D143760D091"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.7.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "69FDAC26-474E-4B84-9383-183135E54F60"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.7.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D1F82C0D-B861-41E2-9005-67BD426D7D4D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3E069B70-871F-4B2D-A6B5-0B08E5D8E68C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.8.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "200181EB-FD48-4D52-ADF7-B04FC1F4E44A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9CF4BA7B-0B35-4FA9-AAF6-8F2AE1A69ED2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:0.9.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "ADDA8FD3-897B-4602-903F-781785FCC4F2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6AA9F0A8-2348-4748-A70F-2B41884BCB8D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8E6126F8-29F8-498F-87C4-120F10A3FFA6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BD85315B-A801-47CB-AF83-F05E613CCBA9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "00AF053F-A640-4C7D-A3E8-37FC768747A7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FC88BE76-DAF0-48BB-A742-27D7AEC44580"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "64FF49D8-D2E3-44CB-B34B-BCF13B31AA58"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C02315A0-E9C4-48E1-8AE5-F77CAAAF71F9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "50A94F95-E788-4730-A500-3B5B7A4239B8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.4.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "79362D9A-25A2-45C9-A4FB-B51D15F46F2F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.4.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F8035711-650E-4E4D-8BDB-2708424CEF8F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.4.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1FA48595-A128-4FB8-BBB3-84DD1EC700DA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.4.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2374C955-5765-46CB-A47B-715832273BEA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.5.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A11DD69D-3C4F-4147-8317-C1852555A96C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.5.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8094B4C9-B953-4524-B7D8-CF455E681521"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.5.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "10150F64-C83D-436E-ADB8-0FD27A6AB0C1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.5.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "43722B4F-90F7-4BDB-A637-4B4B399653B4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.5.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DACAECDE-1C76-45A6-9B4C-2B5591E6E270"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.5.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5AEC0D3F-8A3D-4AA3-8B97-0DE50133A587"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.5.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7D0BA60E-79F8-4904-8A9F-397438BB73BC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4CDD04B2-A3AC-4B1A-9877-FE82EDC9322E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:dennis_royer:dr_wiki:1.7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7C8F572B-2350-4E9A-B2ED-057C547FBB1D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5F1C59B0-CDF2-4F9A-88C7-61E8F18590DB"
}
]
}
]
}
] ,
"references" : [
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/33256" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://typo3.org/teams/security/security-bulletins/typo3-20081222-3/" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://secunia.com/advisories/33256" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://typo3.org/teams/security/security-bulletins/typo3-20081222-3/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}