2024-12-08 03:06:42 +00:00

157 lines
4.4 KiB
JSON

{
"id": "CVE-2003-0509",
"sourceIdentifier": "cve@mitre.org",
"published": "2003-08-07T04:00:00.000",
"lastModified": "2024-11-20T23:44:54.223",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyecci\u00f3n de SQL en Cyberstrong eShop 4.2 y anteriores permite a atacantes remotos robar informaci\u00f3n de autenticaci\u00f3n y ganar privilegios mediante el par\u00e1metro ProductCode en (1) 10expand.asp, (2) 10browse.asp, y (3) 20review.asp."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"baseScore": 10.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cyberstrong:eshop:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.2",
"matchCriteriaId": "3D9F816B-410A-4418-947E-364403E9A186"
}
]
}
]
}
],
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=105709450711395&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/9165",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1007092",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/10098",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/10099",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/10100",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/14101",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/14103",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/14112",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/12485",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=105709450711395&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/9165",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1007092",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/10098",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/10099",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/10100",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/14101",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/14103",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/14112",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/12485",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}