Show plain JSON{"id": "CVE-2013-4676", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2013-08-05T13:22:52.677", "references": [{"url": "http://osvdb.org/95941", "source": "secure@symantec.com"}, {"url": "http://osvdb.org/95942", "source": "secure@symantec.com"}, {"url": "http://www.securityfocus.com/bid/61486", "source": "secure@symantec.com"}, {"url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130801_00", "tags": ["Vendor Advisory"], "source": "secure@symantec.com"}, {"url": "http://osvdb.org/95941", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://osvdb.org/95942", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/61486", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130801_00", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Multiple cross-site scripting (XSS) vulnerabilities in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allow remote attackers to inject arbitrary web script or HTML via vectors involving a (1) custom-reports generation page, (2) Storage Devices creation page, or (3) jobs creation page in the management console; or (4) a Backup Exec server-management page in the beutility console."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de cross-site scripting (XSS) en Symantec Backup Exec v2010 R3 anterior a v2010 R3 SP3 y v2012 anterior a SP2, permite a atacantes remotos inyectar secuencias de comandos web y HTML arbitrarias a trav\u00e9s de vectores que involucran una (1) p\u00e1gina de generaci\u00f3n de informes personalizados, (2) una p\u00e1gina de creaci\u00f3n de dispositivos de almacenamiento, o (3) una p\u00e1gina de creaci\u00f3n de trabajos en la consola de administraci\u00f3n, o (4) una p\u00e1gina de Backup Exec del servidor de administraci\u00f3n en la consola \u201cbeutility\u201d."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:symantec:backup_exec:2010_r3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E34A9FEF-C903-42A6-80EB-E5080F8D5377"}, {"criteria": "cpe:2.3:a:symantec:backup_exec:2010_r3:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FD144D8C-99FA-44DC-949D-DF938AC3C6E8"}, {"criteria": "cpe:2.3:a:symantec:backup_exec:2010_r3:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ADFAEEFA-E438-4611-A42E-A70C8F4D3F68"}, {"criteria": "cpe:2.3:a:symantec:backup_exec:2012:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "632557AF-509E-4FF8-B0CC-A44ABC56645B"}], "operator": "OR"}]}], "sourceIdentifier": "secure@symantec.com"}