2024-07-14 02:06:08 +00:00

97 lines
3.0 KiB
JSON

{
"id": "CVE-2007-3067",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-06-06T01:30:00.000",
"lastModified": "2017-07-29T01:31:57.067",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the Attunement and Key Tracker 0.95 and earlier plugin for EQdkp allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the (1) keyshow, (2) sortkey, and (3) show parameters to index.php."
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la extensi\u00f3n (plugin) Attunement and Key Tracker 0.95 y anteriores para Eqdkp permite a atacantes remotos inyectar secuencias de comandos (script) web o HTML de su elecci\u00f3n a trav\u00e9s de vectores sin especificar, posiblemente involucrando los par\u00e1metros (1) keyshow, (2) sortkey, y (3) show (es el nombre de un par\u00e1metro) de index.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:eqdkp:attunement_and_key:*:*:*:*:*:*:*:*",
"versionEndIncluding": "0.95",
"matchCriteriaId": "918F880C-D8C7-4E81-AEA3-7531755ED386"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/36930",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25538",
"source": "cve@mitre.org"
},
{
"url": "http://sourceforge.net/project/shownotes.php?release_id=512860&group_id=167016",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2045",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34700",
"source": "cve@mitre.org"
}
]
}