2024-12-08 03:06:42 +00:00

132 lines
3.8 KiB
JSON

{
"id": "CVE-2006-4883",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-09-19T21:07:00.000",
"lastModified": "2024-11-21T00:17:00.417",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot BizDirectory allow remote attackers to inject arbitrary web script or HTML via (1) the stylesheet parameter in Feed.php or (2) the message parameter in status.php."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en IDevSpot BizDirectory permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elecci\u00f3n v\u00eda (1) el par\u00e1metro stylesheet en Feed.php o (2) el par\u00e1metro message en status.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:idevspot:bizdirectory:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2DA28DED-F6F0-48BD-97B5-C88D51A556DC"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/21911",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1611",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1016876",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/446223/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20081",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3691",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29002",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/21911",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/1611",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1016876",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/446223/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/20081",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3691",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29002",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}