Show plain JSON{"id": "CVE-2010-4097", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2010-10-27T19:00:11.033", "references": [{"url": "http://www.securityfocus.com/archive/1/514423/100/0/threaded", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/44390", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/62767", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/514423/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/44390", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/62767", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in Aardvark Topsites PHP 5.2.0 and 5.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) title, (3) u, and (4) url parameters. NOTE: the q parameter is already covered by CVE-2009-2302."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de ejecuci\u00f3n de comandos en sitios cruzados (XSS) en index.php en Aardvark Topsites PHP v5.2.0 y v5.2.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s del par\u00e1metro (1) mail , (2) title, (3) u y (4) url. NOTA: el par\u00e1metro q ya est\u00e1 cubierto por CVE-2009-2302."}], "lastModified": "2024-11-21T01:20:14.170", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:avatic:aardvark_topsites_php:5.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "151788A4-3F7E-42E7-B15E-EB7FB19D3AC6"}, {"criteria": "cpe:2.3:a:avatic:aardvark_topsites_php:5.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "98013F5E-37DC-4768-A3CC-85F9FF91A07A"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}