117 lines
3.2 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2003-0509",
"sourceIdentifier": "cve@mitre.org",
"published": "2003-08-07T04:00:00.000",
"lastModified": "2017-07-11T01:29:33.087",
"vulnStatus": "Modified",
"cveTags": [],
2023-04-24 12:24:31 +02:00
"descriptions": [
{
"lang": "en",
"value": "SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyecci\u00f3n de SQL en Cyberstrong eShop 4.2 y anteriores permite a atacantes remotos robar informaci\u00f3n de autenticaci\u00f3n y ganar privilegios mediante el par\u00e1metro ProductCode en (1) 10expand.asp, (2) 10browse.asp, y (3) 20review.asp."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 10.0
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cyberstrong:eshop:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.2",
"matchCriteriaId": "3D9F816B-410A-4418-947E-364403E9A186"
}
]
}
]
}
],
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=105709450711395&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/9165",
"source": "cve@mitre.org"
},
2023-04-24 12:24:31 +02:00
{
"url": "http://securitytracker.com/id?1007092",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/10098",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/10099",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/10100",
"source": "cve@mitre.org"
},
2023-04-24 12:24:31 +02:00
{
"url": "http://www.securityfocus.com/bid/14101",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/14103",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/14112",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/12485",
"source": "cve@mitre.org"
}
]
}