Lucene search

K
cveMitreCVE-2013-5983
HistoryFeb 06, 2014 - 4:10 p.m.

CVE-2013-5983

2014-02-0616:10:58
CWE-79
mitre
web.nvd.nist.gov
27
cve
2013
5983
xss
vulnerabilities
guppy
web script
html
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.003

Percentile

68.2%

Multiple cross-site scripting (XSS) vulnerabilities in GuppY before 4.6.28 allow remote attackers to inject arbitrary web script or HTML via the (1) “an” parameter to agenda.php or (2) cat parameter to mobile/thread.php.

Affected configurations

Nvd
Node
guppyguppyRange4.6.27
OR
guppyguppyMatch2.4
OR
guppyguppyMatch2.4_p1
OR
guppyguppyMatch2.4_p3
OR
guppyguppyMatch2.4_p4
OR
guppyguppyMatch4.0
OR
guppyguppyMatch4.5
OR
guppyguppyMatch4.5.3
OR
guppyguppyMatch4.5.3a
OR
guppyguppyMatch4.5.4
OR
guppyguppyMatch4.5.9
OR
guppyguppyMatch4.5.10
OR
guppyguppyMatch4.5.11
OR
guppyguppyMatch4.5.16
OR
guppyguppyMatch4.6.3
VendorProductVersionCPE
guppyguppy*cpe:2.3:a:guppy:guppy:*:*:*:*:*:*:*:*
guppyguppy2.4cpe:2.3:a:guppy:guppy:2.4:*:*:*:*:*:*:*
guppyguppy2.4_p1cpe:2.3:a:guppy:guppy:2.4_p1:*:*:*:*:*:*:*
guppyguppy2.4_p3cpe:2.3:a:guppy:guppy:2.4_p3:*:*:*:*:*:*:*
guppyguppy2.4_p4cpe:2.3:a:guppy:guppy:2.4_p4:*:*:*:*:*:*:*
guppyguppy4.0cpe:2.3:a:guppy:guppy:4.0:*:*:*:*:*:*:*
guppyguppy4.5cpe:2.3:a:guppy:guppy:4.5:*:*:*:*:*:*:*
guppyguppy4.5.3cpe:2.3:a:guppy:guppy:4.5.3:*:*:*:*:*:*:*
guppyguppy4.5.3acpe:2.3:a:guppy:guppy:4.5.3a:*:*:*:*:*:*:*
guppyguppy4.5.4cpe:2.3:a:guppy:guppy:4.5.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 151

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.003

Percentile

68.2%