2024-12-08 03:06:42 +00:00

155 lines
4.3 KiB
JSON

{
"id": "CVE-2006-3397",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-07-06T20:05:00.000",
"lastModified": "2024-11-21T00:13:31.857",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) title and (2) description parameters when creating a task."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de ejecuci\u00f3n de secuencias de comandos en sitios cruzados (XSS) en Taskjitsu anterior a v2.0.1 permite a atacantes remotos inyectar inyectar secuencias de comandos web y HTML de su elecci\u00f3n a trav\u00e9s de m\u00faltiples par\u00e1metros sin especificar, incluyendo (1) el t\u00edtulo y (2)la descripci\u00f3n de par\u00e1metros cuando se crea una tarea."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pkr_internet:taskjitsu:0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "D9546620-3256-4D85-A144-789A12C5F89D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pkr_internet:taskjitsu:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A03C9348-DD01-4CB3-A5E4-153A8AFA7024"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/20912",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.pkrinternet.com/download/RELEASE-NOTES.txt",
"source": "cve@mitre.org",
"tags": [
"URL Repurposed"
]
},
{
"url": "http://www.securityfocus.com/bid/18818",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2006/2660",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27533",
"source": "cve@mitre.org"
},
{
"url": "https://www.pkrinternet.com/taskjitsu/task/3313",
"source": "cve@mitre.org",
"tags": [
"URL Repurposed"
]
},
{
"url": "http://secunia.com/advisories/20912",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.pkrinternet.com/download/RELEASE-NOTES.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"URL Repurposed"
]
},
{
"url": "http://www.securityfocus.com/bid/18818",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2006/2660",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27533",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.pkrinternet.com/taskjitsu/task/3313",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"URL Repurposed"
]
}
]
}