2024-12-08 03:06:42 +00:00

115 lines
3.8 KiB
JSON

{
"id": "CVE-2011-1896",
"sourceIdentifier": "secure@microsoft.com",
"published": "2011-10-12T02:52:43.347",
"lastModified": "2024-11-21T01:27:16.130",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka \"ExcelTable Reflected XSS Vulnerability.\""
},
{
"lang": "es",
"value": "Vulnerabilidad de ejecuci\u00f3n de comandos en sitios cruzados (XSS) en Microsoft Access Gateway Forefront Unificado (UAG) 2010 Gold, Update 1, Update 2 y SP1 permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s de vectores no especificados. Tambi\u00e9n conocida como \"vulnerabilidad XSS de tabla de Excel reflejada\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:forefront_unified_access_gateway:2010:*:*:*:*:*:*:*",
"matchCriteriaId": "C17E843B-C2FE-433B-B37A-615494AAB211"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:forefront_unified_access_gateway:2010:sp1:*:*:*:*:*:*",
"matchCriteriaId": "96448A86-3D9B-488C-A95C-4CCAE1FE177D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:forefront_unified_access_gateway:2010:update1:*:*:*:*:*:*",
"matchCriteriaId": "8D9218D0-D3C5-400A-A8C4-C25160B746B9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:forefront_unified_access_gateway:2010:update2:*:*:*:*:*:*",
"matchCriteriaId": "C8B9D477-AC0F-4271-ACEF-325C31E8BE40"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/76233",
"source": "secure@microsoft.com"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-079",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12197",
"source": "secure@microsoft.com"
},
{
"url": "http://osvdb.org/76233",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-079",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12197",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}