2025-04-12 12:06:01 +00:00

117 lines
3.4 KiB
JSON

{
"id": "CVE-2014-0362",
"sourceIdentifier": "cret@cert.org",
"published": "2014-05-08T10:55:03.107",
"lastModified": "2025-04-12T10:46:40.837",
"vulnStatus": "Deferred",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability on Google Search Appliance (GSA) devices before 7.0.14.G.216 and 7.2 before 7.2.0.G.114, when dynamic navigation is configured, allows remote attackers to inject arbitrary web script or HTML via input included in a SCRIPT element."
},
{
"lang": "es",
"value": "Vulnerabilidad de XSS en dispositivos Google Search Appliance (GSA) anterior a 7.0.14.G.216 y 7.2 anterior a 7.2.0.G.114, cuando navegaci\u00f3n din\u00e1mica est\u00e1 configurado, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s de entradas incluidas en un elemento SCRIPT."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:google:search_appliance_software:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7.0",
"versionEndExcluding": "7.0.14.g.216",
"matchCriteriaId": "04FE7E1A-AB17-44AE-8FA4-29F895012CD2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:google:search_appliance_software:*:*:*:*:*:*:*:*",
"versionStartIncluding": "7.2",
"versionEndExcluding": "7.2.0.g.114",
"matchCriteriaId": "48B60E4E-51A1-4C49-8C29-DA54DAD7B1B5"
}
]
}
]
}
],
"references": [
{
"url": "http://www.kb.cert.org/vuls/id/673313",
"source": "cret@cert.org",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
},
{
"url": "http://www.securityfocus.com/bid/67176",
"source": "cret@cert.org",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://www.kb.cert.org/vuls/id/673313",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
},
{
"url": "http://www.securityfocus.com/bid/67176",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
}
]
}