115 lines
3.3 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2002-0287",
"sourceIdentifier": "cve@mitre.org",
"published": "2002-05-31T04:00:00.000",
"lastModified": "2024-11-20T23:38:44.197",
2023-04-24 12:24:31 +02:00
"vulnStatus": "Modified",
"cveTags": [],
2023-04-24 12:24:31 +02:00
"descriptions": [
{
"lang": "en",
"value": "pforum 1.14 and earlier does not explicitly enable PHP magic quotes, which allows remote attackers to bypass authentication and gain administrator privileges via an SQL injection attack when the PHP server is not configured to use magic quotes by default."
},
{
"lang": "es",
"value": "pforum 1.14 y anteriores no habilita expl\u00edcitamente las comillas m\u00e1gicas (magic quotes) PHP quotes, lo que permite a atacantes remotos evitar la autenticaci\u00f3n y ganar privilegios de administrador mediante un ataque de inyecci\u00f3n de SQL cuando el servidor no est\u00e1 configurado para usar las comillas m\u00e1gicas."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"baseScore": 10.0,
2023-04-24 12:24:31 +02:00
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
2023-04-24 12:24:31 +02:00
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:powie:pforum:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.14",
"matchCriteriaId": "A3A52CF4-F5C1-40F3-A148-A537F23865B9"
}
]
}
]
}
],
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=101389284625019&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/8203.php",
"source": "cve@mitre.org"
},
{
"url": "http://www.powie.de/news/index.php",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/bid/4114",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=101389284625019&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/8203.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.powie.de/news/index.php",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/bid/4114",
"source": "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}