{ "id": "CVE-2011-3985", "sourceIdentifier": "vultures@jpcert.or.jp", "published": "2011-11-09T23:55:01.960", "lastModified": "2011-11-10T05:00:00.000", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in Plume before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors." }, { "lang": "es", "value": "Vulnerabilidad de ejecuci\u00f3n de secuencias de comandos en sitios cruzado en Plume antes de v1.2.3, permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s de vectores no especificados." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "HIGH", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 2.6 }, "baseSeverity": "LOW", "exploitabilityScore": 4.9, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:plume-cms:plume_cms:*:*:*:*:*:*:*:*", "versionEndIncluding": "1.2.2", "matchCriteriaId": "59A6CF02-B60F-4578-BF26-BF9BA05DA9BC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:plume-cms:plume_cms:1.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "B3B174BD-A02F-46FF-BFD7-0EABDBCAB0C3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:plume-cms:plume_cms:1.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "74437F07-216C-4DE3-8716-51AB78FA43E0" }, { "vulnerable": true, "criteria": "cpe:2.3:a:plume-cms:plume_cms:1.0.4:*:*:*:*:*:*:*", "matchCriteriaId": "737216F6-CC70-4117-BCDE-28F8421FA007" }, { "vulnerable": true, "criteria": "cpe:2.3:a:plume-cms:plume_cms:1.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "39A16986-E49C-438B-8773-170FB4BFD8DE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:plume-cms:plume_cms:1.0.6:*:*:*:*:*:*:*", "matchCriteriaId": "FCFD72DB-1887-4E0D-933D-4BD463B6ECAE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:plume-cms:plume_cms:1.1.3:*:*:*:*:*:*:*", "matchCriteriaId": "87D700AB-EF9C-4B1C-A2E3-D802B91B5967" }, { "vulnerable": true, "criteria": "cpe:2.3:a:plume-cms:plume_cms:1.2:*:*:*:*:*:*:*", "matchCriteriaId": "237536C3-D21B-41FC-9D41-202A59F7D26A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:plume-cms:plume_cms:1.2.1:*:*:*:*:*:*:*", "matchCriteriaId": "DEFBCB71-1048-48AC-9FAE-72F7FE38D940" } ] } ] } ], "references": [ { "url": "http://jvn.jp/en/jp/JVN08307791/index.html", "source": "vultures@jpcert.or.jp" }, { "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2011-000083", "source": "vultures@jpcert.or.jp" } ] }