Show plain JSON{"id": "CVE-2010-3427", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2010-09-16T22:00:03.313", "references": [{"url": "http://osvdb.org/67971", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/67972", "source": "cve@mitre.org"}, {"url": "http://pridels-team.blogspot.com/2010/09/open-classifieds-version-1702-xss-vuln.html", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/41386", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/43176", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/67971", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/67972", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://pridels-team.blogspot.com/2010/09/open-classifieds-version-1702-xss-vuln.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/41386", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/43176", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Multiple cross-site scripting (XSS) vulnerabilities in Open Classifieds 1.7.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) desc, (2) price, (3) title, and (4) place parameters to index.php and the (5) subject parameter to contact.htm, related to content/contact.php."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de ejecuci\u00f3n de secuencias de comandos en sitios cruzados (XSS) en Open Classifieds v1.7.0.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s de los par\u00e1metros (1) desc, (2) price, (3) title, y (4) place a index.php y el parametro subject a contact.htm, relativas a content/contact.php."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:open-classifieds:open_classifieds:1.7.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E997CFAE-86A0-4A9B-A8F3-F8B1B379107C"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}