{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-23T01:39:13.347","vulnerabilities":[{"cve":{"id":"CVE-2010-0963","sourceIdentifier":"cve@mitre.org","published":"2010-03-16T19:00:00.367","lastModified":"2026-06-16T23:17:13.197","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in index.php in dl Download Ticket Service before 0.7 allows remote attackers to inject arbitrary web script or HTML via the t parameter, related to an invalid ticket ID.  NOTE: some of these details are obtained from third party information."},{"lang":"es","value":"Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en index.php en dl Download Ticket Service anterior v0.7 permite a atacantes remotos inyectar código web o HTML de su elección a través del parámetro t, relacionado con un ticket no válido ID. NOTA: algunos de estos detalles se han obtenido de fuentes de terceros."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yuri_d\\'elia:dl:*:*:*:*:*:*:*:*","versionEndIncluding":"0.6","matchCriteriaId":"5AFF571C-6137-4402-A88C-C95A5D353677"},{"vulnerable":true,"criteria":"cpe:2.3:a:yuri_d\\'elia:dl:0.1:*:*:*:*:*:*:*","matchCriteriaId":"C8EB6EC1-51C4-4DD3-B2C8-7811CE710E7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:yuri_d\\'elia:dl:0.2:*:*:*:*:*:*:*","matchCriteriaId":"07A5EFE5-4CFF-4CEB-AC11-5360C48C9535"},{"vulnerable":true,"criteria":"cpe:2.3:a:yuri_d\\'elia:dl:0.3:*:*:*:*:*:*:*","matchCriteriaId":"CA79EF5B-F25A-4577-9D5D-1D95CE790FF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:yuri_d\\'elia:dl:0.4:*:*:*:*:*:*:*","matchCriteriaId":"44CE5630-9766-4A44-A27B-AB9C56468389"},{"vulnerable":true,"criteria":"cpe:2.3:a:yuri_d\\'elia:dl:0.5:*:*:*:*:*:*:*","matchCriteriaId":"E1EE9528-79B0-48FD-B4C9-1185744D9AA7"}]}]}],"references":[{"url":"http://article.gmane.org/gmane.comp.web.dl-ticket-service.general/33","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://freshmeat.net/projects/dl-ticket-service","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://osvdb.org/62884","source":"cve@mitre.org"},{"url":"http://secunia.com/advisories/38898","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/38700","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://article.gmane.org/gmane.comp.web.dl-ticket-service.general/33","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http://freshmeat.net/projects/dl-ticket-service","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http://osvdb.org/62884","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/38898","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/38700","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]}]}}]}