René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

100 lines
3.0 KiB
JSON

{
"id": "CVE-2006-7050",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-02-24T00:28:00.000",
"lastModified": "2017-07-29T01:29:48.063",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) events in forced links (url parameter) that are not properly handled in formatters/wakka.php, and possibly (2) other vectors in wikka.php."
},
{
"lang": "es",
"value": "Vulnerabilida de secuencia de comandos en sitios cruzados (XSS) en WikkaWiki (Wikka Wiki) anterior a 1.1.6.2 permite a atacantes remotos inyectar javascript de su elecci\u00f3n a trav\u00e9s de (1) eventos en enlaces forzados (par\u00e1metro url) que no son manejadas adecuadamente en formatters/wakka.php, y posiblemente (2) otros vectores en wikka.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:wikkawiki:wikkawiki:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.1.6.1",
"matchCriteriaId": "98ABA654-0C36-4611-87A0-4DC94592BB17"
}
]
}
]
}
],
"references": [
{
"url": "http://wikkawiki.org/WikkaReleaseNotes",
"source": "cve@mitre.org"
},
{
"url": "http://wush.net/trac/wikka/changeset/47",
"source": "cve@mitre.org"
},
{
"url": "http://wush.net/trac/wikka/ticket/142",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/18481",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2381",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27227",
"source": "cve@mitre.org"
}
]
}