{ "id": "CVE-2009-1175", "sourceIdentifier": "cve@mitre.org", "published": "2009-03-31T14:09:53.890", "lastModified": "2025-04-09T00:30:58.490", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in the DAAP extension in Banshee 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the server parameter, which is not properly handled in an error message." }, { "lang": "es", "value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en apps/web/vs_diag.cgi en la extensi\u00f3n DAAP en Banshee v1.4.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n a trav\u00e9s del par\u00e1metro \"server\", que no permite un manejo adecuado en un mensaje de error." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "baseScore": 4.3, "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:banshee-project:banshee:1.4.2:*:*:*:*:*:*:*", "matchCriteriaId": "1A13354B-324C-448B-A1DF-9DDB60D914CE" } ] } ] } ], "references": [ { "url": "http://bugzilla.gnome.org/show_bug.cgi?id=577270", "source": "cve@mitre.org" }, { "url": "http://www.openwall.com/lists/oss-security/2009/03/30/2", "source": "cve@mitre.org" }, { "url": "http://bugzilla.gnome.org/show_bug.cgi?id=577270", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.openwall.com/lists/oss-security/2009/03/30/2", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }