{ "id": "CVE-2009-4233", "sourceIdentifier": "cve@mitre.org", "published": "2009-12-08T19:30:00.327", "lastModified": "2009-12-09T05:00:00.000", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php in the YJ Whois component 1.0x and 1.5.x for Joomla! allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php. NOTE: some of these details are obtained from third party information." }, { "lang": "es", "value": "ulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en modules/mod_yj_whois.php en el componente YJ Whois v1.0x y v1.5.x para Joomla! permite a atacantes remotos inyectar c\u00f3digo web o HTMl de su elecci\u00f3n a trav\u00e9s del par\u00e1metro domain de index.php. NOTA: algunos de estos detalles se han obtenido de informaci\u00f3n de terceros." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*", "matchCriteriaId": "2AC7400C-F6AF-4B5E-A34B-0222F94DCC46" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:youjoomla:yj_whois:1.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "51CD1535-1FA4-46F4-985E-46FDDDD8E96A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:youjoomla:yj_whois:1.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "DFE68A5A-083A-4ADD-AF51-8FAADC928048" } ] } ] } ], "references": [ { "url": "http://extensions.joomla.org/extensions/external-contents/domain-search/5774", "source": "cve@mitre.org" }, { "url": "http://www.youjoomla.com/joomla_support/yj-whois-module/4950-xss-security-patch-yj-whois.html", "source": "cve@mitre.org" } ] }