René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

136 lines
4.2 KiB
JSON

{
"id": "CVE-2014-9433",
"sourceIdentifier": "cve@mitre.org",
"published": "2014-12-31T22:59:09.567",
"lastModified": "2018-10-09T19:55:08.560",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9.6, when advanced mod rewrite (AMR) is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) idart, (2) lang, or (3) idcat parameter."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de XSS en cms/front_content.php en Contenido anterior a 4.9.6, cuando 'advanced mod rewrite' (AMR) est\u00e1 deshabilitada, permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s del par\u00e1metro (1) idart, (2) lang, o (3) idcat."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "HIGH",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 2.6
},
"baseSeverity": "LOW",
"exploitabilityScore": 4.9,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:contenido:contendio:4.9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "6F85ABD5-2B2B-4B1E-B5BB-A5ACFE714740"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:contenido:contendio:4.9.1:*:*:*:*:*:*:*",
"matchCriteriaId": "8CB15BEF-0ECE-489C-BD63-8D06577B4BED"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:contenido:contendio:4.9.2:*:*:*:*:*:*:*",
"matchCriteriaId": "2D0FE5FE-0222-46A7-9CA8-E9FEA2CC4E32"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:contenido:contendio:4.9.3:*:*:*:*:*:*:*",
"matchCriteriaId": "A42AC912-354A-4B95-8428-875664F177BB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:contenido:contendio:4.9.4:*:*:*:*:*:*:*",
"matchCriteriaId": "B4F476A9-974C-4FC1-8785-63F5355DD333"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:contenido:contendio:4.9.5:*:*:*:*:*:*:*",
"matchCriteriaId": "89D583E6-B357-4354-8FBD-62A5E1CB5070"
}
]
}
]
}
],
"references": [
{
"url": "http://packetstormsecurity.com/files/129713/CMS-Contenido-4.9.5-Cross-Site-Scripting.html",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://seclists.org/fulldisclosure/2014/Dec/111",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://sroesemann.blogspot.de/2014/12/report-for-advisory-sroeadv-2014-03.html",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.contenido.org/de/cms/CONTENIDO/News/index-c-2044-3.html",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/archive/1/534320/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99497",
"source": "cve@mitre.org"
}
]
}