2024-07-14 02:06:08 +00:00

92 lines
2.6 KiB
JSON

{
"id": "CVE-2002-1167",
"sourceIdentifier": "cve@mitre.org",
"published": "2002-11-04T05:00:00.000",
"lastModified": "2008-09-10T19:13:59.663",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request."
},
{
"lang": "es",
"value": "Vulnerabilidad scripts en sitios cruzados en IBM Web Traffic Express Caching Proxy Server 3.6 y 3.x anteriores a 4.0.1.26 permite a atacantes remotos ejecutar c\u00f3digo como otros mediante una petici\u00f3n HTTP GET."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_caching_proxy_server:3.6:*:*:*:*:*:*:*",
"matchCriteriaId": "F5EFEB97-0E6F-4AFC-A9D6-F1E99FCAC242"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:websphere_caching_proxy_server:4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "57F14A9A-C642-4DA7-AB89-C036F1FC3286"
}
]
}
]
}
],
"references": [
{
"url": "http://www.iss.net/security_center/static/10453.php",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/6000",
"source": "cve@mitre.org"
}
]
}