2024-12-08 03:06:42 +00:00

161 lines
4.5 KiB
JSON

{
"id": "CVE-2006-5127",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-10-03T04:03:00.000",
"lastModified": "2024-11-21T00:17:58.677",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Bartels Schoene ConPresso before 4.0.5a allow remote attackers to inject arbitrary web script or HTML via (1) the nr parameter in detail.php, (2) the msg parameter in db_mysql.inc.php, and (3) the pos parameter in index.php."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Bartels Schoene ConPresso before 4.0.5a permite a un atacante inyectar secuencias de comandos web o HTMl a rta\u00b4ves del par\u00e1metro (1) nr en detail.ph,(2) el par\u00e1metro msg en db_mysql.inc.php, y (3) el par\u00e1metro pos en index.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"baseScore": 6.8,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:conpresso:conpresso_cms:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.0.4a",
"matchCriteriaId": "6FD2DF13-F411-48AF-BC68-EE559C77EBB3"
}
]
}
]
}
],
"references": [
{
"url": "http://download.compresso.de/compresso-4.0.5a.zip",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://secunia.com/advisories/22145",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1671",
"source": "cve@mitre.org"
},
{
"url": "http://www.majorsecurity.de/index_2.php?major_rls=major_rls28",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.securityfocus.com/archive/1/447358/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20273",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2006/3868",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29272",
"source": "cve@mitre.org"
},
{
"url": "http://download.compresso.de/compresso-4.0.5a.zip",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
},
{
"url": "http://secunia.com/advisories/22145",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/1671",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.majorsecurity.de/index_2.php?major_rls=major_rls28",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit"
]
},
{
"url": "http://www.securityfocus.com/archive/1/447358/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/20273",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2006/3868",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29272",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}