mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 01:02:25 +00:00
298 lines
11 KiB
JSON
298 lines
11 KiB
JSON
{
|
|
"id": "CVE-2005-4222",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2005-12-14T11:03:00.000",
|
|
"lastModified": "2025-04-03T01:03:51.193",
|
|
"vulnStatus": "Deferred",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Multiple cross-site scripting (XSS) vulnerabilities in guestbook.cgi in Lars Ellingsen Guestserver 4.13 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified message fields."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
|
|
"baseScore": 4.3,
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "PARTIAL",
|
|
"availabilityImpact": "NONE"
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "NVD-CWE-Other"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:2.07:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "98C7EA57-5631-4051-8119-033207B6701D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:2.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "614AF528-BEB0-43BC-96F7-C831F0518B21"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:2.90:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "845A9FAA-F7EB-4127-A579-761C99D0B1C4"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.01:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4AF95A06-4A38-4A23-95C8-C27840F6B287"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.02:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6E71117D-BD47-4305-896A-B25CEDF75847"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.03:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2112435C-30BE-42A4-8573-87787AFEDF60"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B5763E8B-A691-462E-B5C6-31BCFE504C6F"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.20:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "DA09A92E-76B0-46B3-B5F3-911DA1715B3D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.21:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "47175DC4-CCED-4EC2-8E56-CDE7E55C7D14"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.22:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "7C9BCE16-3B2B-4413-97F5-36B2BA1EAAB5"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.30:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "79EDEA80-FF99-4E3F-ADC8-6C28401CE731"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.31:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "84768091-04A2-477D-A9F6-E9D63300BF94"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.32:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "3BC2AF03-080D-450F-B0BD-056BD4849DC3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.33:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "24824C3A-6D0D-40AD-8D74-A9FA9646D48B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.34:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "8714A446-4A73-47B9-8FE7-CA3CE3E1CD5C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.35:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "69A9C400-C2D3-4EA2-9AEE-755339D2AD90"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.36:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F251BD43-81BF-4B01-8AE5-6005021EDB40"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.40:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9AA68518-D0E3-49A8-8127-0F4058BF90EC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.41:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C678B2B8-3D6C-41DB-9E7E-660B27CE6C25"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.42:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D40777E4-FFB9-4FC7-8FF3-D3723400E07A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.43:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "18410B77-F565-4A67-A05B-DFC50C644564"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.44:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C4042584-E1C1-49F9-A71D-5530465A78C3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.45:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9743B55B-0F03-4D44-98F9-083767AB1738"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.46:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "37591D25-7C81-44F8-A9A5-F400CB1224EC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.47:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E358237C-F84B-4FBA-9713-E6E4832294DC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.48:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "ED5ACC1C-AE93-41E7-9836-71F7CEF62854"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.60:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D2B72D74-E3E9-467C-83A4-CAD94115CB94"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.62:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "7402BB2B-4F04-4F2E-83D9-5202F129FDCE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.65:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "CC7A8942-B299-4270-B3CC-0F6923777FC1"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.66:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "650CB745-569C-499E-8EC3-5D76750F0B39"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.80:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "166104FD-5FA5-4C52-A1BE-466270086090"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.81:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "814DE483-E377-4521-876F-35466D743A2C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.82:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B7F41037-1076-43FF-81C1-F4B49FA0C8F5"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:3.83:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4102F028-2254-46FE-A456-62368203477F"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B029434D-0D97-4E3C-832A-174C73CF967E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:4.01:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4338AC3D-EB37-4181-B2CC-91B4A7261BA6"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:4.05:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "3B14DFEA-BAEB-481F-B778-83145A85D957"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:4.06:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "76766A57-8FC1-47DB-A7EC-16C9D454E3D6"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:4.07:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D07ADE87-734A-4C0B-BE16-F5FD10CB7BDB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:4.08:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "004A519D-5686-4FB3-AD90-8B8EDC09B52E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:4.09:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9D6198CB-6110-44EC-93A9-7D8364EC3B27"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:4.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0894E21E-DAD6-46A8-9734-E3BA57977997"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:lars_ellingsen:guestserver:4.13:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C77CD50F-E705-45EB-8276-0B819C9F4BB7"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://www.securityfocus.com/archive/1/419241/100/0/threaded",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/15821/",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/archive/1/419241/100/0/threaded",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/15821/",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
}
|
|
]
|
|
} |