« Volver al listado

CVE-2010-0349

Estado: ModificadaMedia (4.3)—

Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: this issue could not be reproduced by the vendor, but a patch was provided anyway. The original researcher is reliable.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-0349",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-01-15T20:30:00.373",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN33977065/index.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000002.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/38135",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://webcal.c-3.jp/zeijakusei.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/61629",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN33977065/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000002.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/38135",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://webcal.c-3.jp/zeijakusei.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/61629",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.  NOTE: this issue could not be reproduced by the vendor, but a patch was provided anyway. The original researcher is reliable."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados(XSS) en el C3 Corp. WebCalenderC3 v0.32 y anteriores permite a atacantes remotos inyectar HTML o scripts web a través de vectores desconocidos. NOTA: este problema no pudo ser reproducido por el vendedor, pero se proporciono un parche para el problema. El investigador original del problema es una fuente fiable."
    }
  ],
  "lastModified": "2026-06-16T23:15:59.037",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:c-3.co.jp:webcalenderc3:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9BD6B231-AFE5-48BC-9928-C5ACDFE370F6",
              "versionEndIncluding": "0.32"
            },
            {
              "criteria": "cpe:2.3:a:c-3.co.jp:webcalenderc3:0.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8A784FD-DF9F-4D81-80E7-3AE052FEC531"
            },
            {
              "criteria": "cpe:2.3:a:c-3.co.jp:webcalenderc3:0.31:s2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DA77B43-6E4C-474F-8B1A-FB0FA9578F55"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}