CVE-2014-2236
Published Mar 5, 2014
Last updated 9 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in Askbot before 0.7.49 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) tag or (2) user search forms.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:askbot:askbot:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "446765FF-CBE4-4D64-8A90-88326FCA6761", "versionEndIncluding": "0.7.48" }, { "criteria": "cpe:2.3:a:askbot:askbot:0.7.40:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0C9A0D7-9FFA-47C5-BDB1-DE63B0AFF69B" }, { "criteria": "cpe:2.3:a:askbot:askbot:0.7.41:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B00457E-93E4-41BE-8440-4F1A4D63B71F" }, { "criteria": "cpe:2.3:a:askbot:askbot:0.7.42:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDBE6380-2616-44AC-95BD-D48F23541A16" }, { "criteria": "cpe:2.3:a:askbot:askbot:0.7.43:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06DA39E4-FA8E-4F83-B107-769F000B16F6" }, { "criteria": "cpe:2.3:a:askbot:askbot:0.7.44:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4567B811-66BA-48AD-A887-CFA7E1FD8CBF" }, { "criteria": "cpe:2.3:a:askbot:askbot:0.7.45:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F285503-57E3-4365-84A2-6E3B2F874748" }, { "criteria": "cpe:2.3:a:askbot:askbot:0.7.46:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3DBC465F-ACBF-41DF-ACEF-82F1664AD8C0" }, { "criteria": "cpe:2.3:a:askbot:askbot:0.7.47:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "400742B9-DDF1-4FF0-AB8C-327CF3A14B7D" } ], "operator": "OR" } ] } ]