2024-12-08 03:06:42 +00:00

92 lines
3.1 KiB
JSON

{
"id": "CVE-2006-6996",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-02-12T11:28:00.000",
"lastModified": "2024-11-21T00:24:08.340",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary HTML and web script via the (1) title and (2) newspost parameters to (a) newsadd.php, and the (3) name, title, and (4) comment parameters to (b) news.php, a different set of vectors than CVE-2006-1818. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en warforge.NEWS 1.0 permite a atacantes remotos inyectar scripts web o HTML de su elecci\u00f3n mediante los par\u00e1metros (1) title y (2) newspost en (a) newsadd.php, y par\u00e1metros (3) name, title, y (4) comment en (b) news.php, vectores distintos a CVE-2006-1818.\r\nNOTA: El origen de esta informaci\u00f3n es desconocido; los detalles se han obtenido solamente de informaci\u00f3n de terceros."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:the_war_forge:warforge.news:1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "28ADB3C8-DD45-4417-98B8-6C418CFAB01E"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/19697",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25901",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/19697",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25901",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}