2024-12-08 03:06:42 +00:00

128 lines
3.7 KiB
JSON

{
"id": "CVE-2006-4474",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-08-31T20:04:00.000",
"lastModified": "2024-11-21T00:16:02.627",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin Module Manager, (2) Admin Help, and (3) Search."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Joomla! anterior a 1.0.11 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n mediante par\u00e1metros no especificados en (1) M\u00f3dulo de Administraci\u00f3n, (2) Ayuda de Administraci\u00f3n y (3) B\u00fasqueda."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"baseScore": 6.8,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.0.10",
"matchCriteriaId": "04E1FF2D-21A9-4953-A133-472C92812859"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:joomla:joomla:1.0.9:*:*:*:*:*:*:*",
"matchCriteriaId": "D4007FCB-589A-413D-8009-64404926CA7B"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/21666",
"source": "cve@mitre.org"
},
{
"url": "http://www.joomla.org/content/view/1841/78/",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.joomla.org/content/view/1843/74/",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3408",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28633",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/21666",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.joomla.org/content/view/1841/78/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
},
{
"url": "http://www.joomla.org/content/view/1843/74/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3408",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28633",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}