Show plain JSON{"cve": {"data_type": "CVE", "references": {"reference_data": [{"url": "http://www.autosectools.com/Advisories/eXtplorer.2.1.RC3_Cross-site.Request.Forgery_174.html", "name": "http://www.autosectools.com/Advisories/eXtplorer.2.1.RC3_Cross-site.Request.Forgery_174.html", "tags": ["Exploit"], "refsource": "MISC"}, {"url": "http://www.openwall.com/lists/oss-security/2012/06/25/1", "name": "[oss-security] 20120624 Re: CVE request: CSRF in eXtplorer", "tags": [], "refsource": "MLIST"}, {"url": "http://www.openwall.com/lists/oss-security/2012/06/27/1", "name": "[oss-security] 20120627 Re: CVE request: CSRF in eXtplorer", "tags": [], "refsource": "MLIST"}, {"url": "http://www.openwall.com/lists/oss-security/2012/06/24/1", "name": "[oss-security] 20120624 CVE request: CSRF in eXtplorer", "tags": [], "refsource": "MLIST"}, {"url": "http://www.openwall.com/lists/oss-security/2012/06/26/1", "name": "[oss-security] 20120626 Re: CVE request: CSRF in eXtplorer", "tags": [], "refsource": "MLIST"}, {"url": "http://www.debian.org/security/2012/dsa-2510", "name": "DSA-2510", "tags": [], "refsource": "DEBIAN"}]}, "data_format": "MITRE", "description": {"description_data": [{"lang": "en", "value": "Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "en", "value": "CWE-352"}]}]}, "data_version": "4.0", "CVE_data_meta": {"ID": "CVE-2012-3362", "ASSIGNER": "secalert@redhat.com"}}, "impact": {"baseMetricV2": {"cvssV2": {"version": "2.0", "baseScore": 6.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "severity": "MEDIUM", "impactScore": 6.4, "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}}, "publishedDate": "2012-07-12T20:55Z", "configurations": {"nodes": [{"children": [], "operator": "OR", "cpe_match": [{"cpe23Uri": "cpe:2.3:a:extplorer:extplorer:*:rc3:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true, "versionEndIncluding": "2.1.0"}]}], "CVE_data_version": "4.0"}, "lastModifiedDate": "2012-07-27T03:40Z"}