2024-07-14 02:06:08 +00:00

91 lines
2.7 KiB
JSON

{
"id": "CVE-2009-0328",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-01-29T18:30:02.483",
"lastModified": "2017-09-29T01:33:44.933",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for Database/Sales.mdb."
},
{
"lang": "es",
"value": "ROBS-PROJECTS Digital Sales IPN (tambi\u00e9n conocido como DS-IPN.NET o DS-IPN Paypal Shop) guarda informaci\u00f3n sensible bajo la ra\u00edz de la web con insuficientes controles de acceso, lo que permitir\u00eda atacantes remotos descargar el fichero de la base de datos que contienen las credenciales de usuario a trav\u00e9s de una petici\u00f3n directa a Database/Sales.mdb."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:robs-projects:digital_sales_ipn:_nil_:*:*:*:*:*:*:*",
"matchCriteriaId": "FE0B64FF-1C1B-4DFE-A3AB-BEB06078EDDC"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/33602",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/48082",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/7816",
"source": "cve@mitre.org"
}
]
}