René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

90 lines
2.5 KiB
JSON

{
"id": "CVE-2009-1767",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-05-22T18:30:00.280",
"lastModified": "2017-09-29T01:34:33.403",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter."
},
{
"lang": "es",
"value": "admin/edituser.php en 2daybiz Template Monster Clone no requiere autenticaci\u00f3n administrativa, lo que permite a atacantes remotos modificar cuentas de su elecci\u00f3n a trav\u00e9s de los par\u00e1metros: (1) loginname, (2) password, (3) email, (4) firstname, o (5) lastname."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:2daybiz:template_monster_clone:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E22BADE3-F86E-492F-9E7B-0F92B6D8C2BE"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/34977",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50561",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/8691",
"source": "cve@mitre.org"
}
]
}