« Volver al listado

CVE-2008-6945

Estado: ModificadaMedia (4.3)—

Multiple cross-site scripting (XSS) vulnerabilities in Interchange 5.7 before 5.7.1, 5.6 before 5.6.1, and 5.4 before 5.4.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mv_order_item CGI variable parameter in Core, (2) the country-select widget, or (3) possibly the value specifier when used in the UserTag feature.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-6945",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-08-12T10:30:00.640",
  "references": [
    {
      "url": "http://ftp.icdevgroup.org/interchange/5.7/WHATSNEW",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/49852",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/49853",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/32658",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.icdevgroup.org/i/dev/news?id=ssEkj9j8&mv_arg=00030&mv_pc=96",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/32297",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46598",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46599",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ftp.icdevgroup.org/interchange/5.7/WHATSNEW",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/49852",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/49853",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/32658",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.icdevgroup.org/i/dev/news?id=ssEkj9j8&mv_arg=00030&mv_pc=96",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/32297",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46598",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46599",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site scripting (XSS) vulnerabilities in Interchange 5.7 before 5.7.1, 5.6 before 5.6.1, and 5.4 before 5.4.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mv_order_item CGI variable parameter in Core, (2) the country-select widget, or (3) possibly the value specifier when used in the UserTag feature."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Interchange v5.7 anteriores a v5.7.1, v5.6 anteriores a v5.6.1, y v5.4 anteriores a v5.4.3 permite a atacantes remotos inyectar secuencias de comandos web o HTML de forma arbitraria a través de (1) el parámetro de la variable CGI mv_order_item CGI en Core, (2) el widget country-select, o (3) posiblemente el especificador de valor cuando es utilizado en la característica UserTag."
    }
  ],
  "lastModified": "2026-06-16T23:03:17.280",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:icdevgroup:interchange:5.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA9547B6-91A7-49F5-9013-F7B5B1853F81"
            },
            {
              "criteria": "cpe:2.3:a:icdevgroup:interchange:5.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "665111F3-8F4C-496F-8F1C-F95F63486F12"
            },
            {
              "criteria": "cpe:2.3:a:icdevgroup:interchange:5.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D29016C3-479F-4B05-BC2F-95A0E84E562F"
            },
            {
              "criteria": "cpe:2.3:a:icdevgroup:interchange:5.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61E31CAA-5DE4-408D-88C2-0A97C3B39DFF"
            },
            {
              "criteria": "cpe:2.3:a:icdevgroup:interchange:5.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27D18865-1291-434D-923B-0FE99CF68CEC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}