mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-09-17 18:45:49 +00:00
150 lines
5.1 KiB
JSON
150 lines
5.1 KiB
JSON
{
|
|
"id": "CVE-2007-3963",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2007-07-25T17:30:00.000",
|
|
"lastModified": "2024-11-21T00:34:28.420",
|
|
"vulnStatus": "Modified",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en UseBB 1.0.7, y posiblemente otras versiones 1.0.x, permiten a atacantes remotos inyectar scripts web o HTML de su elecci\u00f3n mediante PATH_INFO (PHP_SELF) en (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, \u00f3 (3) upgrade-0-4.php en install/, vulnerabilidad distinta de CVE-2005-4193."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
|
|
"baseScore": 9.3,
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "COMPLETE",
|
|
"integrityImpact": "COMPLETE",
|
|
"availabilityImpact": "COMPLETE"
|
|
},
|
|
"baseSeverity": "HIGH",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 10.0,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": true,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "NVD-CWE-Other"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D6814F4A-C8B0-4450-8EC7-91EF26F75F13"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0C3D75D7-190D-4EB3-91DD-940B9DCEC07F"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "62A0A3E3-831A-4A68-B9BC-02DE2EA92334"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B5D30AD4-DC83-493B-9324-5432C7B6DACE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "62AD324F-3397-4389-A3C0-E0BC94D2199B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0.5:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1359EA23-4C62-432C-8E8E-7AE8389EFB06"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0.6:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "DB7811B9-46BF-42BF-A9E9-382CC17F1A6A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0.7:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "BE889213-45D4-4DBD-976F-DB061C973E35"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0_rc1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "8B67E6CA-EDCD-4824-BB92-FB58504503FE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0_rc2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F6F3A6AF-FD19-4F78-B956-2E37451994E5"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:usebb:usebb:1.0_rc3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D6308C5A-1627-4D54-B23C-2A533493F71D"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://securityreason.com/securityalert/2915",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/archive/1/474256/100/0/threaded",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/24990",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://securityreason.com/securityalert/2915",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/archive/1/474256/100/0/threaded",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.securityfocus.com/bid/24990",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
}
|
|
]
|
|
} |