Show plain JSON{"id": "CVE-2009-3204", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2009-09-16T17:30:00.407", "references": [{"url": "http://osvdb.org/57177", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/57178", "source": "cve@mitre.org"}, {"url": "http://packetstormsecurity.org/0908-exploits/stivaforum-xss.txt", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/36409", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52613", "source": "cve@mitre.org"}, {"url": "http://osvdb.org/57177", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/57178", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://packetstormsecurity.org/0908-exploits/stivaforum-xss.txt", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/36409", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52613", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) demo.php and (2) forum.php, and the PATH_INFO to (3) include_forum.php."}, {"lang": "es", "value": "M\u00faltiple vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Stiva Forum v1.0 permite a atacantes remotos ejecutar c\u00f3digo web y HTML de su elecci\u00f3n a trav\u00e9s del par\u00e1metro id en (1) demo.php y(2) forum.php, y PATH_INFO en (3) include_forum.php."}], "lastModified": "2025-04-09T00:30:58.490", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:stivaforum:stiva_forum:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "827F106F-A5F3-4F2A-9CCD-0EC19FF9F2DC"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}