2024-07-14 02:06:08 +00:00

112 lines
3.1 KiB
JSON

{
"id": "CVE-2007-0970",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-02-16T01:28:00.000",
"lastModified": "2018-10-16T16:35:48.233",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to execute arbitrary SQL commands via the testID parameter to directions.php, and unspecified parameters to other files that accept GET or POST input."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en WebTester 5.0.20060927 y versiones anteriores permiten a atacantes remotos ejecutar comandos SQL de su elecci\u00f3n a trav\u00e9s del par\u00e1metro testID en directions.php, y par\u00e1metros no especificados en otros ficheros que aceptan entrada GET \u00f3 POST."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:webtester:webtester:*:*:*:*:*:*:*:*",
"versionEndIncluding": "5.0_2006-09-27",
"matchCriteriaId": "FBF33E90-E7A6-4960-9114-E9EFBEA8FCF8"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/33203",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/33204",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/24157",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/2261",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/460078/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/22559",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.vupen.com/english/advisories/2007/0633",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32490",
"source": "cve@mitre.org"
}
]
}