91 lines
2.9 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2005-2398",
"sourceIdentifier": "cve@mitre.org",
"published": "2005-07-27T04:00:00.000",
"lastModified": "2017-07-11T01:32:49.093",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the sid parameter to (2) dataentry.php, (3) export.php, (4) admin.php, (5) conditions.php, (6) spss.php, (7) deletesurvey.php, (8) dumpsurvey.php, or (9) statistics.php, or the lid parameter to (10) labels.php or (11) dumplabel.php."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n de SQL en PHP Surveyor 0.98 permite que atacantes remotos ejecuten comandos SQL mediante: (1) par\u00e1metros sid, start, e id en browse.php, par\u00e1metro sid en (2) dataentry.php, (3) export.php, (4) admin.php, (5) conditions.php, (6) spss.php, (7) deletesurvey.php, (8) dumpsurvey.php, y (9) statistics.php, y par\u00e1metro lid en (10) labels.php y (11) dumplabel.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php_surveyor:php_surveyor:0.98:*:*:*:*:*:*:*",
"matchCriteriaId": "78E91066-133F-4946-B355-A951753A3D3F"
}
]
}
]
}
],
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=112188282401681&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1014538",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/14331",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21444",
"source": "cve@mitre.org"
}
]
}