2024-07-14 02:06:08 +00:00

95 lines
3.1 KiB
JSON

{
"id": "CVE-2007-4240",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-08-08T22:17:00.000",
"lastModified": "2017-07-29T01:32:48.097",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The check_logout function in class/auth.php in Help Center Live (hcl) 2.1.3a sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to delete administrative users and have other unspecified impact via certain requests to (1) admin/departments.php, (2) admin/operators.php, and other unspecified scripts. NOTE: some of these details are obtained from third party information."
},
{
"lang": "es",
"value": "La funci\u00f3n check_logout del class/auth.php en el Help Center Live (hcl) 2.1.3a env\u00eda una redirecci\u00f3n al navegador web pero no sale cuando las credenciales administrativas se pierden, lo que permite a atacantes remotos borrar usuarios administrativos y tener otros impactos sin especificar a trav\u00e9s de ciertas peticiones a 1) admin/departments.php, (2) admin/operators.php y otros scripts sin especificar. NOTA: algunos de estos detalles se obtienen a partir de la informaci\u00f3n de terceros."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:help_center_live:help_center_live:2.1.3a:*:*:*:*:*:*:*",
"matchCriteriaId": "F6CFB050-31E1-4014-A46A-C03919098745"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/39400",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26352",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/25225",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35833",
"source": "cve@mitre.org"
}
]
}