mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-08-04 08:44:25 +00:00
144 lines
5.8 KiB
JSON
144 lines
5.8 KiB
JSON
{
|
|
"data_type": "CVE",
|
|
"data_format": "MITRE",
|
|
"data_version": "4.0",
|
|
"CVE_data_meta": {
|
|
"ID": "CVE-2020-36530",
|
|
"TITLE": "SevOne Network Management System Alert Summary sql injection",
|
|
"REQUESTER": "cna@vuldb.com",
|
|
"ASSIGNER": "cna@vuldb.com",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"generator": "vuldb.com",
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "SevOne",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "Network Management System",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "5.7.2.0"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.1"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.2"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.3"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.4"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.5"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.6"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.7"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.8"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.9"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.10"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.11"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.12"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.13"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.14"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.15"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.16"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.17"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.18"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.19"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.20"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.21"
|
|
},
|
|
{
|
|
"version_value": "5.7.2.22"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-89 SQL Injection"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. The manipulation leads to sql injection. The attack can be initiated remotely."
|
|
}
|
|
]
|
|
},
|
|
"credit": "Calvin Phang",
|
|
"impact": {
|
|
"cvss": {
|
|
"version": "3.1",
|
|
"baseScore": "6.3",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
|
|
}
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"url": "http://seclists.org/fulldisclosure/2020/Oct/5",
|
|
"refsource": "MISC",
|
|
"name": "http://seclists.org/fulldisclosure/2020/Oct/5"
|
|
},
|
|
{
|
|
"url": "https://vuldb.com/?id.162262",
|
|
"refsource": "MISC",
|
|
"name": "https://vuldb.com/?id.162262"
|
|
}
|
|
]
|
|
}
|
|
} |