René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

104 lines
3.1 KiB
JSON

{
"id": "CVE-2008-2861",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-06-25T12:36:00.000",
"lastModified": "2018-10-11T20:44:50.077",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4) txtEmail parameters to login.asp."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de secuencia de comandos en sitios cruzados (XSS) en eLineStudio Site Composer (ESC) 2.6 y anteriores; permiten a atacantes remotos inyectar secuencias de comandos Web o HTML de su elecci\u00f3n mediante los par\u00e1metros (1) topic y (2) button de ansFAQ.asp y los par\u00e1metros (3) id y (4) txtEmail de login.asp."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:elinestudio:site_composer:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.6",
"matchCriteriaId": "F0FD8D51-A4F6-464D-93E3-1EA6C2C50A45"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:elinestudio:site_composer:2.5:*:*:*:*:*:*:*",
"matchCriteriaId": "D3623BB8-EB16-4DD2-8DA7-02947FA1DB4F"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/3957",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/493473/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/29812",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43191",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/5859",
"source": "cve@mitre.org"
}
]
}