René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

84 lines
2.5 KiB
JSON

{
"id": "CVE-2006-0122",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-01-09T11:03:00.000",
"lastModified": "2011-03-08T02:29:22.097",
"vulnStatus": "Modified",
"evaluatorSolution": "Vendor provided solution:\r\n\r\n\"Liquid Development has identified this vulnerability in all shipping versions of AquiferCMS and coded a software fix. The fix will be included in all releases of AquiferCMS built on or after January 24, 2006. Customers should contact Liquid Development to obtain the fix for this vulnerability. For more information visit www.aquifercms.com.\" \r\n",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:aquifer_cms:aquifer_cms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FB376587-855F-4BF2-A9CB-9B46C0AF34F2"
}
]
}
]
}
],
"references": [
{
"url": "http://attrition.org/pipermail/vim/2006-January/000509.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/16162",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/0074",
"source": "cve@mitre.org"
}
]
}