93 lines
2.6 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2002-0622",
"sourceIdentifier": "cve@mitre.org",
"published": "2002-07-03T04:00:00.000",
"lastModified": "2018-10-12T21:31:32.690",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka \"OWC Package Command Execution\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:commerce_server:2000:*:*:*:*:*:*:*",
"matchCriteriaId": "AF65806C-05BF-4EB7-976B-3346F2D64886"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:commerce_server:2000:sp1:*:*:*:*:*:*",
"matchCriteriaId": "C73B40C1-B8D7-46FB-B327-8C93F2ACDD9D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:commerce_server:2000:sp2:*:*:*:*:*:*",
"matchCriteriaId": "DD28CDF4-00E9-4F61-8201-76FB44544A33"
}
]
}
]
}
],
"references": [
{
"url": "http://www.iss.net/security_center/static/9425.php",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/5111",
"source": "cve@mitre.org"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-033",
"source": "cve@mitre.org"
}
]
}