- Description
- Cross-site scripting (XSS) vulnerability in the category page in VCD-db 0.98 and earlier allows remote attackers to inject arbitrary web script or HTML via the batch parameter.
- Source
- cve@mitre.org
- NVD status
- Deferred
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vcd-db:vcd-db:0.97:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "401E0BDE-7B5D-4C1A-B335-64D787D1841B"
},
{
"criteria": "cpe:2.3:a:vcd-db:vcd-db:0.98:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "497C16ED-A62F-43A8-81DE-B8DDD49C2E87"
},
{
"criteria": "cpe:2.3:a:vcd-db:vcd-db:0.961:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5644D862-A159-4C49-A3B4-41CA3FAD36E2"
},
{
"criteria": "cpe:2.3:a:vcd-db:vcd-db:0.971:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "234B5C4D-F55E-4135-9F63-8A83C0D54A7C"
},
{
"criteria": "cpe:2.3:a:vcd-db:vcd-db:0.972:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D3903B15-41C1-458F-823B-63BDC5CA339A"
},
{
"criteria": "cpe:2.3:a:vcd-db:vcd-db:0.973:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5B23471-1487-421A-8991-6D2D167BFDE3"
}
],
"operator": "OR"
}
]
}
]