René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

92 lines
2.8 KiB
JSON

{
"id": "CVE-2006-4587",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-09-06T22:04:00.000",
"lastModified": "2011-03-08T02:41:25.687",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 4.2.4, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) description parameter in unspecified modules or the (2) solution parameter in the HelpDesk module."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en vtiger CRM 4.2.4, y posiblemente anteriores, permitem a un atacante remoto inyectar secuencias de comandos web o HTML a trav\u00e9s del (1) par\u00e1metro description en modulos no especificados o el (2) par\u00e1metro solution en el modulo HelpDesk."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:vtiger:vtiger_crm:4.2:*:*:*:*:*:*:*",
"matchCriteriaId": "D8B3F151-0398-42C7-B194-FF528696D1E7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:vtiger:vtiger_crm:4.2.4:*:*:*:*:*:*:*",
"matchCriteriaId": "57840915-C75E-4D62-A017-E60DD1396D34"
}
]
}
]
}
],
"references": [
{
"url": "http://www.security-net.biz/adv/D3906a.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/19829",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3444",
"source": "cve@mitre.org"
}
]
}