2024-07-14 02:06:08 +00:00

96 lines
2.8 KiB
JSON

{
"id": "CVE-2007-1231",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-03-03T19:19:00.000",
"lastModified": "2018-10-16T16:37:27.453",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) database name, (2) table name, (3) ViewName, (4) view, (5) trigger, and (6) function fields in main.php and certain other files."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en SQLiteManager 1.2.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML a trav\u00e9s de los campos (1) database name, (2) table name, (3) ViewName, (4) view, (5) trigger, y (6) function en main.php y otros ciertos archivos."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sqlitemanager:sqlitemanager:1.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A51506D7-74C3-4E32-9DA7-7D3B028AAF1C"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/34634",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/2366",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/461304/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/22731",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32692",
"source": "cve@mitre.org"
}
]
}