Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:boxes_project:boxes:7.x-1.0:*:*:*:*:*:*:*", "matchCriteriaId": "5DB2E816-647F-4135-8D8E-E008A8E4693C", "vulnerable": true}, {"criteria": "cpe:2.3:a:boxes_project:boxes:7.x-1.0:beta1:*:*:*:*:*:*", "matchCriteriaId": "22238DF9-1EF5-484C-96CB-47E73E7E42D0", "vulnerable": true}, {"criteria": "cpe:2.3:a:boxes_project:boxes:7.x-1.0:beta2:*:*:*:*:*:*", "matchCriteriaId": "EAFC74A1-E521-4254-B4BA-625DFC1BD193", "vulnerable": true}, {"criteria": "cpe:2.3:a:boxes_project:boxes:7.x-1.0:beta3:*:*:*:*:*:*", "matchCriteriaId": "F336E064-346A-4B5F-8B28-AF45E08F8D60", "vulnerable": true}, {"criteria": "cpe:2.3:a:boxes_project:boxes:7.x-1.0:beta4:*:*:*:*:*:*", "matchCriteriaId": "D6217FC6-011A-4E4E-98D1-BEA6EC6F6AF7", "vulnerable": true}, {"criteria": "cpe:2.3:a:boxes_project:boxes:7.x-1.0:beta5:*:*:*:*:*:*", "matchCriteriaId": "02897B93-7243-42B3-ADB8-1290A0029059", "vulnerable": true}, {"criteria": "cpe:2.3:a:boxes_project:boxes:7.x-1.0:beta6:*:*:*:*:*:*", "matchCriteriaId": "DB698B2C-4699-4648-BFC2-6721DEA45376", "vulnerable": true}, {"criteria": "cpe:2.3:a:boxes_project:boxes:7.x-1.0:beta7:*:*:*:*:*:*", "matchCriteriaId": "29C4FA04-2B02-4AD7-A401-1F6D7542CBC0", "vulnerable": true}, {"criteria": "cpe:2.3:a:boxes_project:boxes:7.x-1.0:beta8:*:*:*:*:*:*", "matchCriteriaId": "6C32353E-AC9C-4CED-A91B-4E114C20C7D9", "vulnerable": true}, {"criteria": "cpe:2.3:a:boxes_project:boxes:7.x-1.x:dev:*:*:*:*:*:*", "matchCriteriaId": "4D573E81-5F13-4236-9EC4-F32A8332F4CA", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*", "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}], "cveTags": [], "descriptions": [{"lang": "en", "value": "Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter."}, {"lang": "es", "value": "Ejecuci\u00f3n de comandos en sitios cruzados (XSS) en el m\u00f3dulo Boxes v7.x-1.x antes v7.x-1.1 para Drupal que permite a usuarios remotos autenticados, con permiso para administrar o editar los permisos de las cajas, inyectar secuencias de comandos web o HTML a trav\u00e9s del par\u00e1metro sujeto."}], "id": "CVE-2013-0259", "lastModified": "2025-04-11T00:51:21.963", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "LOW", "cvssData": {"accessComplexity": "HIGH", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "NONE", "baseScore": 2.1, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:H/Au:S/C:N/I:P/A:N", "version": "2.0"}, "exploitabilityScore": 3.9, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true}]}, "published": "2013-03-27T21:55:02.160", "references": [{"source": "secalert@redhat.com", "url": "http://drupal.org/node/1897016"}, {"source": "secalert@redhat.com", "tags": ["Patch", "Vendor Advisory"], "url": "http://drupal.org/node/1903300"}, {"source": "secalert@redhat.com", "url": "http://drupalcode.org/project/boxes.git/commitdiff/456ff8e"}, {"source": "secalert@redhat.com", "url": "http://www.openwall.com/lists/oss-security/2013/02/05/1"}, {"source": "secalert@redhat.com", "url": "http://www.securityfocus.com/bid/57642"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://drupal.org/node/1897016"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch", "Vendor Advisory"], "url": "http://drupal.org/node/1903300"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://drupalcode.org/project/boxes.git/commitdiff/456ff8e"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.openwall.com/lists/oss-security/2013/02/05/1"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/57642"}], "sourceIdentifier": "secalert@redhat.com", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-79"}], "source": "nvd@nist.gov", "type": "Primary"}]}