2024-12-08 03:06:42 +00:00

126 lines
3.7 KiB
JSON

{
"id": "CVE-2009-4651",
"sourceIdentifier": "cve@mitre.org",
"published": "2010-02-22T21:30:00.377",
"lastModified": "2024-11-21T01:10:08.347",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) color, (2) img, or (3) url BBCode tags in unspecified vectors."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de ejecuci\u00f3n de secuencias de comandos en sitios cruzados (XSS) en el componente de Joomla! Webee Comments (com_webeecomment) v1.1.1, v1.2, y v2.0 para Joomla!, permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s de las etiquetas (1) color, (2) img y (3) url BBCode en vectores no especificados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:onnogroen:com_webeecomment:1.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "D5F00E91-0C0A-401E-9752-542D2E2FB399"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:onnogroen:com_webeecomment:1.2:*:*:*:*:*:*:*",
"matchCriteriaId": "4E3D9C8C-86D5-4220-A842-8A1A59438553"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:onnogroen:com_webeecomment:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "92F20B49-CE94-474A-83C1-B16DE1C603B7"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2AC7400C-F6AF-4B5E-A34B-0222F94DCC46"
}
]
}
]
}
],
"references": [
{
"url": "http://jeffchannell.com/Joomla/webee-111-multiple-vulnerabilities.html",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.securityfocus.com/bid/38204",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://jeffchannell.com/Joomla/webee-111-multiple-vulnerabilities.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit"
]
},
{
"url": "http://www.securityfocus.com/bid/38204",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit"
]
}
]
}