René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

117 lines
3.2 KiB
JSON

{
"id": "CVE-2005-3971",
"sourceIdentifier": "cve@mitre.org",
"published": "2005-12-03T19:03:00.000",
"lastModified": "2017-07-20T01:29:07.673",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:citrix:metaframe_secure_access_manager:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "02CEEF28-CB2C-47A4-A0F1-B6AB9C8A132B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:citrix:metaframe_secure_access_manager:2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "D5123FE8-FA68-4844-8F70-ED1F5C1086E0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:citrix:metaframe_secure_access_manager:2.2:*:*:*:*:*:*:*",
"matchCriteriaId": "5F6523EC-2F19-4C9C-9139-483DDCC1667E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:citrix:nfuse:1.0:*:elite:*:*:*:*:*",
"matchCriteriaId": "27E22341-F1AD-4551-8EA6-7106FA590A21"
}
]
}
]
}
],
"references": [
{
"url": "http://securitytracker.com/id?1015304",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1015305",
"source": "cve@mitre.org"
},
{
"url": "http://support.citrix.com/article/CTX108208",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/15664",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2005/2676",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/23396",
"source": "cve@mitre.org"
}
]
}