2024-07-14 02:06:08 +00:00

103 lines
2.9 KiB
JSON

{
"id": "CVE-2007-5182",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-10-03T14:17:00.000",
"lastModified": "2017-07-29T01:33:26.850",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in mail.asp in Netkamp Emlak Scripti allows remote attackers to inject arbitrary web script or HTML via the (1) Email parameter, and possibly the (2) Ad, (3) Soyad, (4) Konu, and (5) Mesaj parameters to iletisim.asp."
},
{
"lang": "es",
"value": "Una vulnerabilidad de tipo cross-site scripting (XSS) en el archivo mail.asp en Netkamp Emlak Scripti, permite a atacantes remotos inyectar script web o HTML arbitrario por medio del (1) par\u00e1metro Email, y posiblemente los par\u00e1metros (2) Ad, (3) Soyad, (4) Konu, y (5) Mesaj en el archivo iletisim.asp."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:netkamp:netkamp_emlak_scripti:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B3C93E12-1AED-4114-BAD0-408FF5A5CB3E"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/37406",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.org/0709-exploits/netkamp-sql.txt",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/27032",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/25875",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3320",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36881",
"source": "cve@mitre.org"
}
]
}