mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
133 lines
4.5 KiB
JSON
133 lines
4.5 KiB
JSON
{
|
|
"id": "CVE-2007-4886",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2007-09-14T00:17:00.000",
|
|
"lastModified": "2017-09-29T01:29:24.500",
|
|
"vulnStatus": "Modified",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbitrary PHP code via a (1) UNC share pathname, or a (2) ftp, (3) ftps, or (4) ssh2.sftp URL, in the pilih parameter, for which PHP remote file inclusion is blocked only for http URLs."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Vulnerabilidad de lista negra incompleta en index.php de AuraCMS 1.x y probablemente 2.x permite a atacantes remotos ejecutar c\u00f3digo PHP de su elecci\u00f3n mediante (1) nombre de ruta UNC compartida, \u00f3 un URL (2) ftp, (3) ftps, \u00f3 (4) ssh2.sftp, en el par\u00e1metro pilih, para el que la inclusi\u00f3n remota de archivo en PHP est\u00e1 bloqueada solamente para URLs http."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "PARTIAL",
|
|
"integrityImpact": "PARTIAL",
|
|
"availabilityImpact": "PARTIAL",
|
|
"baseScore": 6.8
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 6.4,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": true,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-94"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:auracms:auracms:1.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F28DAF5D-6FB2-40A3-AE26-83B2B653CBE7"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:auracms:auracms:1.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E5F58C57-054F-4C64-9B45-CC1B0A0ABA56"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:auracms:auracms:1.2:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6A7ADCAB-79C7-456C-A71B-C93C865B32D2"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:auracms:auracms:1.3:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1CD4278C-D878-47D8-8AFB-FB0C8FD79052"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:auracms:auracms:1.5:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "95C81747-2524-4F3A-94B6-BE5C7C8C1BEE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:auracms:auracms:1.6_beta:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "79E8BA55-608F-4E37-AA5D-25902135CAFB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:auracms:auracms:1.61:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0F49F7B4-6267-4BD5-AA97-0853A33DDA84"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:auracms:auracms:1.62:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0C93C4BB-2CC5-48AA-9440-A2C2199F6B06"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:auracms:auracms:2.0:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "79834D18-B70E-4ADC-B458-EF26ED1016C2"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:auracms:auracms:2.1:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1E62CD9C-DE5F-4E6D-9D37-A1B028C1D9DC"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://osvdb.org/40506",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://www.auracms.org/?pilih=news&aksi=lihat&id=117",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "https://www.exploit-db.com/exploits/4390",
|
|
"source": "cve@mitre.org"
|
|
}
|
|
]
|
|
} |