Lucene search

K
cveMitreCVE-2009-2571
HistoryJul 22, 2009 - 5:30 p.m.

CVE-2009-2571

2009-07-2217:30:00
CWE-79
mitre
web.nvd.nist.gov
26
cve
xss vulnerabilities
verliadmin 0.3.7
verliadmin 0.3.8
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.002

Percentile

60.0%

Multiple cross-site scripting (XSS) vulnerabilities in index.php in VerliAdmin 0.3.7 and 0.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the URI, (2) the q parameter, (3) the nick parameter, or (4) the nick parameter in a bantest action.

Affected configurations

Nvd
Node
verliadminverliadminMatch0.3.7
OR
verliadminverliadminMatch0.3.8
VendorProductVersionCPE
verliadminverliadmin0.3.7cpe:2.3:a:verliadmin:verliadmin:0.3.7:*:*:*:*:*:*:*
verliadminverliadmin0.3.8cpe:2.3:a:verliadmin:verliadmin:0.3.8:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.002

Percentile

60.0%

Related for CVE-2009-2571