2024-12-08 03:06:42 +00:00

185 lines
5.6 KiB
JSON

{
"id": "CVE-2007-6312",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-12-11T21:46:00.000",
"lastModified": "2024-11-21T00:39:50.620",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 allows remote attackers to inject arbitrary web script or HTML via the username field."
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencia de comandos en sitios cruzaods (XSS) en la p\u00e1gina de entrada en el portal Web Reporting Tools en Websense Enterprise y Web Security Suite 6.3 permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s del campo username."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:websense:enterpise:6.3:*:*:*:*:*:*:*",
"matchCriteriaId": "4C401DD1-356A-4D49-92B6-79CDEBB0A950"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:websense:enterpise:6.3.1:*:*:*:*:*:*:*",
"matchCriteriaId": "55C994DC-41FA-48AB-AF96-D09F18F41C8B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:websense:reporting_tools:6.3:*:*:*:*:*:*:*",
"matchCriteriaId": "04921824-6D2F-4F58-B9CC-9B7514C125D3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:websense:reporting_tools:6.3.1:*:*:*:*:*:*:*",
"matchCriteriaId": "B693707D-84FF-4877-B6B1-DE573930B173"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:websense:web_security_suite:6.3:*:*:*:*:*:*:*",
"matchCriteriaId": "5C6B33BD-95AF-46E9-9438-0142DE27B3D3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:websense:web_security_suite:6.3.1:*:*:*:*:*:*:*",
"matchCriteriaId": "83262C61-49ED-4D16-BC10-FBEBD602D5E5"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/28019",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3432",
"source": "cve@mitre.org"
},
{
"url": "http://www.liquidmatrix.org/blog/2007/12/10/advisory-websense-xss-vulnerability/",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/archive/1/484824/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/26793",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1019066",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/4158",
"source": "cve@mitre.org"
},
{
"url": "http://www.websense.com/SupportPortal/SupportKbs/1840.aspx",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38936",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28019",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3432",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.liquidmatrix.org/blog/2007/12/10/advisory-websense-xss-vulnerability/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/archive/1/484824/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/26793",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1019066",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/4158",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.websense.com/SupportPortal/SupportKbs/1840.aspx",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38936",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}