{ "id": "CVE-2007-6498", "sourceIdentifier": "cve@mitre.org", "published": "2007-12-20T20:46:00.000", "lastModified": "2018-10-15T21:54:40.867", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2) loginname parameters to Hosting/Addreseller.asp, (3) the sortfield parameter to accounts/accountmanager.asp, (4) the GateWayID parameter to OpenApi/GatewayVariables.asp, and possibly (5) unspecified vectors to IIS/iibind.asp." }, { "lang": "es", "value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en Hosting Controller 6.1 Hot fix 3.3 y anteriores permite a usuarios remotos validados ejecutar comandos SQL de su elecci\u00f3n a trav\u00e9s de los par\u00e1metros (1) email y (2) loginname en Hosting/Addreseller.asp, (3) el par\u00e1metro sortfield en accounts/accountmanager.asp, (4) el par\u00e1metro GateWayID en OpenApi/GatewayVariables.asp, y posiblemente (5) vectores no especificados en IIS/iibind.asp." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 7.5 }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-89" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:hosting_controller:hosting_controller:6.1_hotfix_3.3:*:*:*:*:*:*:*", "matchCriteriaId": "B0D49DC9-27D0-4FDB-A273-FA161B0BC815" } ] } ] } ], "references": [ { "url": "http://securityreason.com/securityalert/3474", "source": "cve@mitre.org" }, { "url": "http://securitytracker.com/id?1019222", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/archive/1/485028/100/0/threaded", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/26862", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39036", "source": "cve@mitre.org" }, { "url": "https://www.exploit-db.com/exploits/4730", "source": "cve@mitre.org" } ] }