Lucene search

K
friendsofphpOpenJS FoundationFRIENDSOFPHP:IISOFT:YII2-GII:CVE-2015-3397
HistoryMay 10, 2015 - 3:41 a.m.

JSON Data encoded for use in HTML was not safe to use in IE6/IE7, possible XSS attacks

2015-05-1003:41:39
OpenJS Foundation
github.com
5

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.2

Confidence

Low

EPSS

0.002

Percentile

56.9%

Affected configurations

Vulners
Node
yiisoftyii2_giiRange<2.0.4
VendorProductVersionCPE
yiisoftyii2_gii*cpe:2.3:a:yiisoft:yii2_gii:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.2

Confidence

Low

EPSS

0.002

Percentile

56.9%

Related for FRIENDSOFPHP:IISOFT:YII2-GII:CVE-2015-3397