{ "id": "CVE-2014-2024", "sourceIdentifier": "cve@mitre.org", "published": "2014-03-14T14:55:04.377", "lastModified": "2018-10-09T19:43:05.517", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to shared-apartments-rooms/." }, { "lang": "es", "value": "Vulnerabilidad de XSS en classes/controller/error.php en Open Classifieds 2 anterior a 2.1.3 permite a atacantes remotos inyectar script Web o HTML arbitrarios a trav\u00e9s de PATH_INFO hacia shared-apartments-rooms/." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:*:*:*:*:*:*:*:*", "versionEndIncluding": "2.1.2", "matchCriteriaId": "3F344FE4-1B7A-4D76-A03C-6DE41201CE3A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.0:*:*:*:*:*:*:*", "matchCriteriaId": "5CE392C8-EFEF-4B7B-B54B-75A9EE64C128" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "6C454DBC-BEE9-4074-9613-BE69048DA0AF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "BDD9E7D2-812F-4F77-9383-ABC584D8EE50" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "8C83B09C-ADE8-40B9-8400-792129668F3D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.0.4:*:*:*:*:*:*:*", "matchCriteriaId": "C8DD433E-FB01-431C-92E3-A4070A882F4F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "C9E17F5C-CE2C-4260-9D40-0A4637AD8ADC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.0.6:*:*:*:*:*:*:*", "matchCriteriaId": "88764A03-40FF-4C3D-A57A-1D5E88662E78" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.0.7:*:*:*:*:*:*:*", "matchCriteriaId": "5FC57D04-D645-4EA0-931B-1BF9A83AF40A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.0.8:*:*:*:*:*:*:*", "matchCriteriaId": "DA46428A-A545-4639-85A7-C56D84A57A16" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.1:*:*:*:*:*:*:*", "matchCriteriaId": "4B5F8D93-9F23-479A-AC33-0079AFEC4863" }, { "vulnerable": true, "criteria": "cpe:2.3:a:openclassifieds:open_classifieds_2:2.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "581FDF54-DC29-4235-9CE0-A92AD429A52D" } ] } ] } ], "references": [ { "url": "http://www.securityfocus.com/archive/1/531428/100/0/threaded", "source": "cve@mitre.org" }, { "url": "https://github.com/open-classifieds/openclassifieds2/commit/45ee8fb601a91b8a4238229580a32a4fd8d96ef9", "source": "cve@mitre.org", "tags": [ "Exploit", "Patch" ] }, { "url": "https://github.com/open-classifieds/openclassifieds2/issues/556", "source": "cve@mitre.org", "tags": [ "Exploit" ] }, { "url": "https://www.htbridge.com/advisory/HTB23204", "source": "cve@mitre.org", "tags": [ "Exploit" ] } ] }