2024-07-14 02:06:08 +00:00

92 lines
2.8 KiB
JSON

{
"id": "CVE-2007-3423",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-06-26T23:30:00.000",
"lastModified": "2008-11-15T06:52:33.267",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function reads (a) an internal IM, or a message from a (b) guest or (c) removed member, which has unknown impact and remote attack vectors."
},
{
"lang": "es",
"value": "cgi-bin/cgi-lib/instantmessage.pl en web-app.org WebAPP anterior a 0.9.9.7 utiliza el campo From de mensaje instant\u00e1neo como inicio del nombre de archivo .dat cuando la funci\u00f3n (1) imview2 o (2) imview3 lee (a) un IM (mensaje instant\u00e1neo) interno, o un mensaje desde un usario (b) invitado o (c) borrado, lo cual tiene impacto y vectores de ataque remotos desconocidos."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:web-app.org:webapp:*:*:*:*:*:*:*:*",
"versionEndIncluding": "0.9.9.6",
"matchCriteriaId": "148D57A7-D6B9-41A5-8B65-DCE7072E1C31"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/45409",
"source": "cve@mitre.org"
},
{
"url": "http://www.web-app.org/cgi-bin/index.cgi?action=forum&board=how_to&op=display&num=9458",
"source": "cve@mitre.org"
},
{
"url": "http://www.web-app.org/downloads/WebAPPv0.9.9.7.zip",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
}
]
}