2024-12-08 03:06:42 +00:00

135 lines
4.0 KiB
JSON

{
"id": "CVE-2017-9072",
"sourceIdentifier": "cve@mitre.org",
"published": "2017-05-18T17:29:00.117",
"lastModified": "2024-11-21T03:35:16.267",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Two CalendarXP products have XSS in common parts of HTML files. CalendarXP FlatCalendarXP through 9.9.290 has XSS in iflateng.htm and nflateng.htm. CalendarXP PopCalendarXP through 9.8.308 has XSS in ipopeng.htm and npopeng.htm."
},
{
"lang": "es",
"value": "Dos productos CalendarXP presentan un problema de tipo XSS en partes comunes de archivos HTML. CalendarXP FlatCalendarXP hasta versi\u00f3n 9.9.290, presenta un XSS en los archivos iflateng.htm y nflateng.htm. CalendarXP PopCalendarXP hasta versi\u00f3n 9.8.308, presenta un XSS en los archivos ipopeng.htm y npopeng.htm."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 2.7
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:calendarxp:flatcalendarxp:*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.9.290",
"matchCriteriaId": "D25067B4-08DC-4113-89D8-42891466C508"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:calendarxp:popcalendarxp:*:*:*:*:*:*:*:*",
"versionEndIncluding": "9.8.308",
"matchCriteriaId": "762D9C64-6108-41BC-A2A7-73DAC50809CF"
}
]
}
]
}
],
"references": [
{
"url": "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/102632",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/victorwon/calendarxp/issues/2",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
},
{
"url": "http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/102632",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/victorwon/calendarxp/issues/2",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
}
]
}