René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

83 lines
2.4 KiB
JSON

{
"id": "CVE-2014-8365",
"sourceIdentifier": "cve@mitre.org",
"published": "2014-10-20T18:55:03.633",
"lastModified": "2014-10-24T12:51:44.157",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Xornic Contact Us allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) email parameter to contact.php or (3) PATH_INFO to setup.php, related to the \"PHP_SELF\" variable."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de XSS en Xornic Contact Us permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s del par\u00e1metro (1) name o (2) email en contact.php o (3) PATH_INFO en setup.php, relacionado con la variable 'PHP_SELF'."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:xornic:contact_us:1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A06EA264-A026-4E35-B4AB-EDCC3DF007D1"
}
]
}
]
}
],
"references": [
{
"url": "http://packetstormsecurity.com/files/127003/Xornic-Contact-Us-Form-CAPTCHA-Bypass-XSS.html",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Jun/40",
"source": "cve@mitre.org"
}
]
}