René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

112 lines
3.6 KiB
JSON

{
"id": "CVE-2008-2410",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-05-22T13:09:00.000",
"lastModified": "2017-08-08T01:31:01.450",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the servlet engine and Web container in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors."
},
{
"lang": "es",
"value": "Vulnerabilidad de ejecuci\u00f3n de comandos en sitios cruzados (XSS) en el motor de servlets y el contenedor Web en el servicio Web Server de IBM Lotus Domino anterior a 7.0.3 FP1 y 8.x anterior al 8.0.1, permite a usuarios autenticados remotamente inyectar secuencias de comandos web y HTML de su elecci\u00f3n a trav\u00e9s de vectores no especificados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:lotus_domino_web_server:*:*:*:*:*:*:*:*",
"versionEndIncluding": "8.0",
"matchCriteriaId": "DC0B5C12-70BE-461B-9C58-E013BCA05D4B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:lotus_domino_web_server:7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "3FB51B8A-58CF-4F26-B1D3-9C572658EE03"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:lotus_domino_web_server:7.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "2F86B710-6F83-4145-BABD-A742C0BB88A9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:lotus_domino_web_server:7.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "1E23B4E9-2AF5-407F-87AE-4F49F78B07A9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:lotus_domino_web_server:7.0.3:*:*:*:*:*:*:*",
"matchCriteriaId": "E344283F-CC85-424D-B19D-A41366937653"
}
]
}
]
}
],
"references": [
{
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg21303296",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/29311",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/1597",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42553",
"source": "cve@mitre.org"
}
]
}