Lucene search

K
cveRedhatCVE-2014-0149
HistoryMay 05, 2014 - 5:06 p.m.

CVE-2014-0149

2014-05-0517:06:05
CWE-79
redhat
web.nvd.nist.gov
18
cve
2014
0149
cross-site scripting
xss
vulnerabilities
red hat
jboss
web framework kit
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

49.1%

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.

Affected configurations

Nvd
Node
redhatjboss_web_framework_kitMatch2.5.0
VendorProductVersionCPE
redhatjboss_web_framework_kit2.5.0cpe:2.3:a:redhat:jboss_web_framework_kit:2.5.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

49.1%

Related for CVE-2014-0149