René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

88 lines
2.7 KiB
JSON

{
"id": "CVE-2009-2366",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-07-08T15:30:01.343",
"lastModified": "2017-09-19T01:29:04.280",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers to execute arbitrary SQL commands via the (1) password parameter in 1.1 and (2) p_password parameter in 1.5. NOTE: some of these details are obtained from third party information."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyecci\u00f3n SQL en login.asp en DataCheck Solutions ForumPal FE v1.1 y ForumPal v.1.5 permite a atacantes remotos ejecutar comandos SQL a su elecci\u00f3n a trav\u00e9s de (1) par\u00e1metro password en v1.1 y (2) par\u00e1metro p_password en v.1.5. NOTA: algunos de estos detalles se han obtenido exclusivamente de informaci\u00f3n de terceros."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:datachecknh:forumpal:1.5:*:*:*:*:*:*:*",
"matchCriteriaId": "902F1AA0-8056-4A42-8730-A7C1B0076698"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:datachecknh:forumpal_fe:1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "2170FD4B-44CB-4EB3-A610-F37B2A98CDFC"
}
]
}
]
}
],
"references": [
{
"url": "http://www.exploit-db.com/exploits/9024",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51403",
"source": "cve@mitre.org"
}
]
}