CVE-2013-3645
Published Jun 14, 2013
Last updated 11 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in the Orchard.Comments module in Orchard before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Source
- vultures@jpcert.or.jp
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:orchardproject:orchard:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "539E782C-A237-431A-8C40-CF4349DACD65", "versionEndIncluding": "1.6" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FBCD2EE9-D3F1-48C7-B180-B180E939F00B" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82610413-EBE7-4319-B63E-8E9B237DA790" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9BD0A43E-2EA3-4A68-96BB-0A981F635D35" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F86C15D0-3FFA-4FAE-B4D6-B5180D061BDE" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "822D03B1-1FC6-43BA-B031-EE622E8AAB16" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6F6CC14-867D-4573-B0FB-7FD6D82F1100" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8BFA6EB5-13A9-4D08-9228-AC5856BC4624" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D4467A8-D305-41BE-BE2E-AD8C57C73E5B" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF210DB9-188F-4FD9-A6F8-7E0259351F5E" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE5C8ABA-ABC7-4189-844D-A452896FCE28" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86AFDD1A-F50C-4483-8D7D-7F27A9AD24A6" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:1.41:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80B98296-A6AB-497B-818F-255D0923FD2C" }, { "criteria": "cpe:2.3:a:orchardproject:orchard:1.42:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F93115C-7B9E-4F19-AF1F-C12201909FDE" } ], "operator": "OR" } ] } ]