René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

103 lines
3.1 KiB
JSON

{
"id": "CVE-2007-5472",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-10-22T19:46:00.000",
"lastModified": "2021-04-09T16:52:36.850",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the Server component in CA Host-Based Intrusion Prevention System (HIPS) before 8.0.0.93 allows remote attackers to inject arbitrary web script or HTML via requests that are written to logs for later display in the log viewer."
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el componente Server de CA Host-Based Intrusion Prevention System (HIPS) versiones anteriores a 8.0.0.93 permite a atacantes remotos inyectar scripts web o HTML de su elecci\u00f3n mediante peticiones que son escritas en ficheros de trazas para ser mostradas posteriormente en el visor de ficheros de trazas."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:broadcom:host-based_intrusion_prevention_system:*:*:*:*:*:*:*:*",
"versionEndIncluding": "8",
"matchCriteriaId": "4B2DD0DC-4F04-430B-B91B-D7A0643C4532"
}
]
}
]
}
],
"references": [
{
"url": "http://securitytracker.com/id?1018839",
"source": "cve@mitre.org"
},
{
"url": "http://supportconnectw.ca.com/public/cahips/infodocs/cahips-secnotice.asp",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/archive/1/482536/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/26134",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3547",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/37285",
"source": "cve@mitre.org"
}
]
}