2024-04-04 08:46:00 +00:00

137 lines
4.2 KiB
JSON

{
"id": "CVE-2007-1188",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-03-02T21:18:00.000",
"lastModified": "2011-03-08T02:51:27.187",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has unknown impact, possibly related to \"search form hijacking\"."
},
{
"lang": "es",
"value": "WebAPP anterior a 0.9.9.5 permite a atacantes remotos enviar el formularios de entrada de b\u00fasqueda que no son validados para (1) composition o(2) length, lo cual tiene un impacto desconocido, posiblemente relacionado con \"secuestro de formulario de b\u00fasqueda\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9:*:*:*:*:*:*:*",
"matchCriteriaId": "79090F47-9D7C-42F4-A64E-6633A3CF73F0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.1:*:*:*:*:*:*:*",
"matchCriteriaId": "FA8C727E-412A-4044-8FE9-63C4FD8D4779"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.2:*:*:*:*:*:*:*",
"matchCriteriaId": "87B45A79-F173-44D6-8737-22DDE3877AE7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "A343A7FD-E5BA-4C84-913B-2B56AFA555FD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.3:*:*:*:*:*:*:*",
"matchCriteriaId": "9216F8B4-8B90-4DF0-9135-CFBBBE8E199E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.3.1:*:*:*:*:*:*:*",
"matchCriteriaId": "1E7890A9-68D0-4882-9BF0-EE90C32DA554"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.3.2:*:*:*:*:*:*:*",
"matchCriteriaId": "124D5CC6-651A-4C59-975E-D23500DE0EA9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.4:*:*:*:*:*:*:*",
"matchCriteriaId": "DC102B4E-32FB-4424-8BF9-1E69A95961D4"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/33299",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/24080",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/22563",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.vupen.com/english/advisories/2007/0604",
"source": "cve@mitre.org"
},
{
"url": "http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=250",
"source": "cve@mitre.org"
}
]
}