Lucene search

K
nvd[email protected]NVD:CVE-2011-4709
HistoryDec 08, 2011 - 7:55 p.m.

CVE-2011-4709

2011-12-0819:55:05
CWE-79
web.nvd.nist.gov
4

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.01

Percentile

83.9%

Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject arbitrary web script or HTML via the (1) SITE_NAME parameter to admin_index.php, or the (2) return and (3) search parameters to index.php. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
hotarusearch_pluginMatch1.3
AND
hotaruhotaru_cmsMatch1.4.2
VendorProductVersionCPE
hotarusearch_plugin1.3cpe:2.3:a:hotaru:search_plugin:1.3:*:*:*:*:*:*:*
hotaruhotaru_cms1.4.2cpe:2.3:a:hotaru:hotaru_cms:1.4.2:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.01

Percentile

83.9%