2024-07-14 02:06:08 +00:00

112 lines
3.2 KiB
JSON

{
"id": "CVE-2007-4281",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-08-09T21:17:00.000",
"lastModified": "2011-03-08T02:58:06.187",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors."
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en KnowledgeTree Open Source 3.4 y 3.4.1 permite a atacantes remotos inyectar scripts web o HTML de su elecci\u00f3n mediante el campo login en la p\u00e1gina login, y otros vectores no especificados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:knowledgetree:open_source:3.4:*:*:*:*:*:*:*",
"matchCriteriaId": "F89D7851-0348-4B79-BE4D-511E8939EB36"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:knowledgetree:open_source:3.4.1:*:*:*:*:*:*:*",
"matchCriteriaId": "7AE71D30-15CF-4744-82A6-DF8C7D706439"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/36579",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26333",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://sourceforge.net/forum/forum.php?forum_id=722865",
"source": "cve@mitre.org"
},
{
"url": "http://sourceforge.net/project/shownotes.php?release_id=530698&group_id=107851",
"source": "cve@mitre.org"
},
{
"url": "http://support.ktdms.com/browse/KTS-2178",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25231",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2812",
"source": "cve@mitre.org"
}
]
}