2024-07-14 02:06:08 +00:00

101 lines
2.8 KiB
JSON

{
"id": "CVE-2007-3631",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-07-10T00:30:00.000",
"lastModified": "2017-09-29T01:29:04.860",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyecci\u00f3n SQL en index.php en GameSiteScript (gss) 3.1 y anteriores permite a atacantes remotos ejecutar comandos SQL de su elecci\u00f3n a trav\u00e9s del par\u00e1metro params, relacionado con la falta de validaci\u00f3n de entrada del campo id."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:gamesitescript:gamesitescript:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.1",
"matchCriteriaId": "C5929DA3-F5F7-4A2D-9EA2-3A66053E8B84"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/36362",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25983",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/24807",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2460",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35292",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/4159",
"source": "cve@mitre.org"
}
]
}