mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 17:21:36 +00:00
175 lines
6.2 KiB
JSON
175 lines
6.2 KiB
JSON
{
|
|
"id": "CVE-2010-1625",
|
|
"sourceIdentifier": "secalert@redhat.com",
|
|
"published": "2010-06-24T12:30:01.767",
|
|
"lastModified": "2024-11-21T01:14:50.260",
|
|
"vulnStatus": "Modified",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Cross-site scripting (XSS) vulnerability in LXR Cross Referencer before 0.9.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the search body and the results page for a search, a different vulnerability than CVE-2009-4497 and CVE-2010-1448."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en LXR Cross Referencer anterior v0.9.7 permite a atacantes remotos inyecatr c\u00f3digo web o HTML de su elecci\u00f3n a trav\u00e9s de vectores relacionados con el cuerpo ode b\u00fasqueda y la p\u00e1gina de resultado para una busqueda, una vulnerabilidad diferente que than CVE-2009-4497 y CVE-2010-1448."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
|
|
"baseScore": 4.3,
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "PARTIAL",
|
|
"availabilityImpact": "NONE"
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": true
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-79"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:*:*:*:*:*:*:*:*",
|
|
"versionEndIncluding": "0.9.6",
|
|
"matchCriteriaId": "B8CA1B98-8DCB-4AEB-8834-C8B0A4395F64"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:0.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "615A0E3B-5931-4B51-87AA-BFF399BE3762"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:0.3.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "EE2ECB28-6473-4D73-8AC8-CF8732BD0428"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:0.7:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6B4BA9B7-0D11-4910-8D8D-AF42A8886DC3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:0.8:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "AB08278A-4ACA-4C1B-889D-D1AAB90D3A46"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:0.9:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "527C1006-423D-4BF8-A454-BADEC3D37D0E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:0.9.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9A75D32B-5F56-435F-A670-F14143D8359D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:0.9.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B19DB649-5F29-4723-8871-3942ADAE0C40"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:0.9.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1357B088-5884-413F-91FE-DE91D3D7AC6B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:0.9.4:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0122AB54-946D-4F45-96C2-53A79E93B82B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:malcom_box:lxr_cross_referencer:0.9.5:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4AAB75A8-E13E-4C2D-BCD1-FA5BF389793D"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://marc.info/?l=oss-security&m=127289957223005&w=2",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://marc.info/?l=oss-security&m=127316953819027&w=2",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://sourceforge.net/projects/lxr/files/stable/lxr-0.9.7/ChangeLog/download",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://www.openwall.com/lists/oss-security/2010/05/03/7",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://www.openwall.com/lists/oss-security/2010/05/06/2",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://www.openwall.com/lists/oss-security/2010/05/14/3",
|
|
"source": "secalert@redhat.com"
|
|
},
|
|
{
|
|
"url": "http://marc.info/?l=oss-security&m=127289957223005&w=2",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://marc.info/?l=oss-security&m=127316953819027&w=2",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://sourceforge.net/projects/lxr/files/stable/lxr-0.9.7/ChangeLog/download",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.openwall.com/lists/oss-security/2010/05/03/7",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.openwall.com/lists/oss-security/2010/05/06/2",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.openwall.com/lists/oss-security/2010/05/14/3",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
}
|
|
]
|
|
} |