Show plain JSON{"id": "CVE-2014-1855", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2014-05-20T14:55:05.427", "references": [{"url": "http://forum.seopanel.in/viewtopic.php?f=7&t=10978", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://packetstormsecurity.com/files/126706/Seo-Panel-3.4.0-Cross-Site-Scripting.html", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/58706", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/532119/100/0/threaded", "source": "cve@mitre.org"}, {"url": "https://www.htbridge.com/advisory/HTB23200", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "http://forum.seopanel.in/viewtopic.php?f=7&t=10978", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://packetstormsecurity.com/files/126706/Seo-Panel-3.4.0-Cross-Site-Scripting.html", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/58706", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/532119/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.htbridge.com/advisory/HTB23200", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel before 3.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) capcheck parameter to directories.php or (2) keyword parameter to proxy.php."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de XSS en Seo Panel anterior a 3.5.0 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s del par\u00e1metro (1) capcheck hacia directories.php o (2) keyword hacia proxy.php."}], "lastModified": "2025-04-12T10:46:40.837", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:seopanel:seo_panel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68F54972-D048-490F-A7E4-7A5AA345F771", "versionEndIncluding": "3.4.0"}, {"criteria": "cpe:2.3:a:seopanel:seo_panel:3.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8F8D34F-DC94-43A6-B13C-3FD08350F604"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}