René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

113 lines
3.4 KiB
JSON

{
"id": "CVE-2006-5080",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-09-29T00:07:00.000",
"lastModified": "2017-07-20T01:33:30.697",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the search function in Six Apart Movable Type 3.3 to 3.32, and Movable Type Enterprise 1.01 and 1.02, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la funci\u00f3n de b\u00fasqueda en Six Apart Movable Type 3.3 a 3.32, y Movable Type Enterprise 1.01 y 1.02, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n mediante vectores no especificados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:six_apart:movable_type:3.3:*:*:*:*:*:*:*",
"matchCriteriaId": "DE37614D-A959-4B4A-BF2E-9F3C1072BA20"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:six_apart:movable_type:3.32:*:*:*:*:*:*:*",
"matchCriteriaId": "13132B94-C271-46F7-9450-FBA1FCBB914E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:six_apart:movable_type:enterprise_1.01:*:*:*:*:*:*:*",
"matchCriteriaId": "D4DE5399-013C-431F-A893-1F2D34AC6DA2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:six_apart:movable_type:enterprise_1.02:*:*:*:*:*:*:*",
"matchCriteriaId": "A338416F-166B-4D47-BBD5-A9B2068E4BE9"
}
]
}
]
}
],
"references": [
{
"url": "http://jvn.jp/jp/JVN%2368295640/index.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20228",
"source": "cve@mitre.org"
},
{
"url": "http://www.sixapart.com/movabletype/news/2006/09/mt_333-mte_103_updates.html",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2006/3779",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29183",
"source": "cve@mitre.org"
}
]
}