René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

79 lines
2.7 KiB
JSON

{
"id": "CVE-2007-3983",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-07-25T17:30:00.000",
"lastModified": "2017-07-29T01:32:39.613",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Absolute path traversal vulnerability in the Data Dynamics DDActiveReports2.ActiveReport.2 (ActiveReports) ActiveX control in arpro2.dll in ActiveReports 2.0 Professional Edition 2.5.0.1308 (SP5 RC) allows remote attackers to create or overwrite arbitrary files via a full pathname in an argument to the SaveLayout method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
},
{
"lang": "es",
"value": "Vulnerabilidad de salto de ruta absoluta en el control ActiveX Data Dynamics DDActiveReports2.ActiveReport.2 (ActiveReports) en arpro2.dll de ActiveReports 2.0 Professional Edition 2.5.0.1308 (SP5 RC) permite a atacantes remotos crear o sobre-escribir ficheros de su elecci\u00f3n mediante una ruta completa en un argumento del m\u00e9todo SaveLayout.\r\nNOTA: El origen de esta informaci\u00f3n es desconocido; los detalles se han obtenido solamente de informaci\u00f3n de terceros."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:datadynamics:activereports:2.0:*:professional_edition_2.5.0.1308_sp5:*:*:*:*:*",
"matchCriteriaId": "67D044C0-3D2D-45A2-973C-A1CD87F8DDBF"
}
]
}
]
}
],
"references": [
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36056",
"source": "cve@mitre.org"
}
]
}