2024-12-08 03:06:42 +00:00

124 lines
3.7 KiB
JSON

{
"id": "CVE-2006-5122",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-10-03T04:03:00.000",
"lastModified": "2024-11-21T00:17:57.513",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Mercury SiteScope 8.2 (8.1.2.0) allow remote authenticated users to inject arbitrary web script or HTML via (1) \"any field create name field\" except \"create new group name\" or (2) any description field."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en ercury SiteScope 8.2 (8.1.2.0) permite a un usuario validado inyectar secuencias de comandos web o HTML de su elecci\u00f3n a trav\u00e9s de (1)\"cualquier campo crea un campo conocido\" excepto \"crear nuevo nombre ed grupo\" o (2) cualquier descripci\u00f3n de campo."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:N",
"baseScore": 4.9,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 6.8,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hp:mercury_sitescope:8.2_8.1.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "4131AC50-8F4D-45BC-95D7-0B1D8A4B9D3C"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/22215",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1670",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/447397/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20275",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3888",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29295",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/22215",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/1670",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/447397/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/20275",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3888",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29295",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}