René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

91 lines
3.0 KiB
JSON

{
"id": "CVE-2008-1409",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-03-20T10:44:00.000",
"lastModified": "2017-09-29T01:30:41.473",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php and (7) profile.php in members/; (8) index.php and (9) fullview.php in news/; and (10) nopermission.php."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de salto de directorio en el tema Default de Exero CMS 1.0.1 permite a atacantes remotos incluir y ejecutar ficheros locales de su elecci\u00f3n mediante la utilizaci\u00f3n de secuencias de salto de directorio en el par\u00e1metro theme de (1) index.php, (2) editpassword.php, y (3) avatar.php en usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php y (7) profile.php en members/; (8) index.php y (9) fullview.php en news/; y (10) nopermission.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:exero:exero_cms:1.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "EB145AE2-B4B1-449B-9A53-C5E2B4EFF571"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/28273",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0909/references",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41238",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/5265",
"source": "cve@mitre.org"
}
]
}