2024-12-08 03:06:42 +00:00

144 lines
4.0 KiB
JSON

{
"id": "CVE-2006-3036",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-06-15T10:02:00.000",
"lastModified": "2024-11-21T00:12:40.210",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades cross-site scripting (XSS) en 35mmslidegallery 6.0 permite a atacantes remotos inyectar script web o HTML de forma arbitraria a trav\u00e9s (1) del par\u00e1metro imgdir en (a) index.php, y los par\u00e1metros (2) w, (3) h y (4) t en (b) popup.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"baseScore": 5.8,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:andy_mack:35mmslidegallery:6.0:*:*:*:*:*:*:*",
"matchCriteriaId": "3B1FFCAC-5652-46BB-8617-AE5A336EA903"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/20652",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://securityreason.com/securityalert/1100",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/26507",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/26508",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/436959/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/18414",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27127",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/20652",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://securityreason.com/securityalert/1100",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/26507",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/26508",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/436959/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/18414",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27127",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}