cvelist/2020/7xxx/CVE-2020-7803.json
2020-05-07 18:01:15 +00:00

96 lines
2.9 KiB
JSON

{
"CVE_data_meta": {
"ASSIGNER": "vuln@krcert.or.kr",
"ID": "CVE-2020-7803",
"STATE": "PUBLIC",
"TITLE": "Zoneplayer ActiveX File Download Vulnerability"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "IMGTech Co,Ltd",
"product": {
"product_data": [
{
"product_name": "Zoneplayer",
"version": {
"version_data": [
{
"version_value": "2.0.1.4 and prior"
}
]
}
}
]
}
}
]
}
},
"credit": [
{
"lang": "eng",
"value": "Yu, Donghyun"
}
],
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.ocx of IMGTech Co,Ltd Zoneplayer allows attacker to cause arbitrary code execution."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-20 Improper Input Validation"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"name": "https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35346",
"url": "https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35346"
},
{
"refsource": "CONFIRM",
"name": "http://www.zoneplayer.co.kr/",
"url": "http://www.zoneplayer.co.kr/"
}
]
},
"source": {
"discovery": "UNKNOWN"
}
}