Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:usebb:usebb:1.0:*:*:*:*:*:*:*", "matchCriteriaId": "D6814F4A-C8B0-4450-8EC7-91EF26F75F13", "vulnerable": true}, {"criteria": "cpe:2.3:a:usebb:usebb:1.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "0C3D75D7-190D-4EB3-91DD-940B9DCEC07F", "vulnerable": true}, {"criteria": "cpe:2.3:a:usebb:usebb:1.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "62A0A3E3-831A-4A68-B9BC-02DE2EA92334", "vulnerable": true}, {"criteria": "cpe:2.3:a:usebb:usebb:1.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "B5D30AD4-DC83-493B-9324-5432C7B6DACE", "vulnerable": true}, {"criteria": "cpe:2.3:a:usebb:usebb:1.0.4:*:*:*:*:*:*:*", "matchCriteriaId": "62AD324F-3397-4389-A3C0-E0BC94D2199B", "vulnerable": true}, {"criteria": "cpe:2.3:a:usebb:usebb:1.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "1359EA23-4C62-432C-8E8E-7AE8389EFB06", "vulnerable": true}, {"criteria": "cpe:2.3:a:usebb:usebb:1.0.6:*:*:*:*:*:*:*", "matchCriteriaId": "DB7811B9-46BF-42BF-A9E9-382CC17F1A6A", "vulnerable": true}, {"criteria": "cpe:2.3:a:usebb:usebb:1.0.7:*:*:*:*:*:*:*", "matchCriteriaId": "BE889213-45D4-4DBD-976F-DB061C973E35", "vulnerable": true}, {"criteria": "cpe:2.3:a:usebb:usebb:1.0_rc1:*:*:*:*:*:*:*", "matchCriteriaId": "8B67E6CA-EDCD-4824-BB92-FB58504503FE", "vulnerable": true}, {"criteria": "cpe:2.3:a:usebb:usebb:1.0_rc2:*:*:*:*:*:*:*", "matchCriteriaId": "F6F3A6AF-FD19-4F78-B956-2E37451994E5", "vulnerable": true}, {"criteria": "cpe:2.3:a:usebb:usebb:1.0_rc3:*:*:*:*:*:*:*", "matchCriteriaId": "D6308C5A-1627-4D54-B23C-2A533493F71D", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en UseBB 1.0.7, y posiblemente otras versiones 1.0.x, permiten a atacantes remotos inyectar scripts web o HTML de su elecci\u00f3n mediante PATH_INFO (PHP_SELF) en (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, \u00f3 (3) upgrade-0-4.php en install/, vulnerabilidad distinta de CVE-2005-4193."}], "id": "CVE-2007-3963", "lastModified": "2025-04-09T00:30:58.490", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 9.3, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 10.0, "obtainAllPrivilege": true, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}]}, "published": "2007-07-25T17:30:00.000", "references": [{"source": "cve@mitre.org", "url": "http://securityreason.com/securityalert/2915"}, {"source": "cve@mitre.org", "url": "http://www.securityfocus.com/archive/1/474256/100/0/threaded"}, {"source": "cve@mitre.org", "url": "http://www.securityfocus.com/bid/24990"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://securityreason.com/securityalert/2915"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/archive/1/474256/100/0/threaded"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/24990"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "NVD-CWE-Other"}], "source": "nvd@nist.gov", "type": "Primary"}]}