mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 01:02:25 +00:00
145 lines
4.9 KiB
JSON
145 lines
4.9 KiB
JSON
{
|
|
"id": "CVE-2008-0180",
|
|
"sourceIdentifier": "cret@cert.org",
|
|
"published": "2008-02-05T00:00:00.000",
|
|
"lastModified": "2008-09-05T21:34:24.670",
|
|
"vulnStatus": "Analyzed",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados en themes/_unstyled/templates/init.vm en Liferay Portal 4.3.6. Permite a usuarios autenticados remotamente inyectar scripts web o HTMLs arbitrarios a trav\u00e9s del campo Greeting en un Perfil de Usuario."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "PARTIAL",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 4.3
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": true
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-79"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:*:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C94E89A8-FD42-4A27-A57E-D25700EC27E4"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:1.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E1561FBB-3E05-4DE9-8785-9D1C149B466C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:2.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5CD9FA47-07E1-42D1-8B9A-F31119D2C4D9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:2.1.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A8340091-8C00-42AD-8709-866044D4A3B8"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:2.1.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9C414660-1C6E-4371-800F-1C0FBFAEF5DD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:2.2.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "266E1E93-431D-4C04-8288-077837158A09"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:3.6.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "7A512412-F8BA-4187-8E71-040C5641EF04"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:4.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B9265D3B-45C3-4D60-8B6E-E17C7C94CA9A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:4.1.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E2050C79-6FCD-4C05-86A2-F8AF2BBEB735"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:4.1.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "569A80EE-0B9B-49BD-AEB0-8B07D8DA7CE3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:4.3.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "987419EB-E5FC-472A-AFFA-47D4D8799F61"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:liferay:liferay_enterprise_portal:4.3.6:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C86D1BEF-DDC0-4622-8399-A23F7EFDE0F2"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://support.liferay.com/browse/LEP-4738",
|
|
"source": "cret@cert.org"
|
|
},
|
|
{
|
|
"url": "http://www.kb.cert.org/vuls/id/732449",
|
|
"source": "cret@cert.org",
|
|
"tags": [
|
|
"US Government Resource"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/27546",
|
|
"source": "cret@cert.org"
|
|
}
|
|
]
|
|
} |