René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

95 lines
3.3 KiB
JSON

{
"id": "CVE-2007-3888",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-07-18T23:30:00.000",
"lastModified": "2018-10-15T21:31:55.443",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the search action, possibly related to the term parameter to index.php; or (2) an anonymous blog entry, possibly involving the (a) posted_by, (b) subject, and (c) content parameters to index.php; as demonstrated by the onmouseover attribute of certain elements. NOTE: some of these details are obtained from third party information."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Insanely Simple Blog 0.5 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s de la (1) acci\u00f3n de b\u00fasqueda, posiblemente relacionado con el par\u00e1metro term en index.php; o (2) un entrada an\u00f3nima en el blos, posiblemente afectando los par\u00e1metros (a) posted_by, (b) subject, y (c) content en index.php; como se demostr\u00f3 con el atributo onmouseover de ciertos elementos. NOTA: Algunos de estos detalles se obtuvieron de terceras fuentes de informaci\u00f3n."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:insanely_simple_blog:insanely_simple_blog:*:*:*:*:*:*:*:*",
"versionEndIncluding": "0.5",
"matchCriteriaId": "65C9BB0F-6A56-4782-8292-502104BC207D"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/2904",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/473868/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/24934",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35448",
"source": "cve@mitre.org"
}
]
}