René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

87 lines
3.1 KiB
JSON

{
"id": "CVE-2006-3135",
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com",
"published": "2006-07-13T21:05:00.000",
"lastModified": "2017-07-20T01:32:04.477",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in CMS Mundo 1.0 build 008, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter in the (a) news module, (2) searchstring parameter in (b) the search module, (3) id parameter in (c) the webshop module, (4) username parameter in (d) index.php, and (5) Name, (6) Address, (7) Zip, (8) City, (9) Country, and (10) Email fields during (e) a user profile update."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n de SQL en CMS Mundo 1.0 build 008, y posiblemente otras versiones, permiten a atacantes remotos ejecutar \u00f3rdenes SQL de su elecci\u00f3n mediante el par\u00e1metro (1) 'news_id' en el m\u00f3dulo (a) 'news', el par\u00e1metro (2) 'searchstring' en el m\u00f3dulo (b) 'search', el par\u00e1metro (3) 'id' en el mulo (c) 'webshop', el par\u00e1metro (4) 'username' en (d) index.php, y los campos (5) Nombre, (6) Direcci\u00f3n, (7) C\u00f3digo Postal, (8) Ciudad, (9) Pa\u00eds, y (10) Email durante una (e) actualizaci\u00f3n del perfil de usuario.\r\n"
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:hotwebscripts:cms_mundo:1.0_build_008:*:*:*:*:*:*:*",
"matchCriteriaId": "D64A62CB-D395-4BC2-A99D-B1D568C13C85"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/1236",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2783",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27712",
"source": "PSIRT-CNA@flexerasoftware.com"
}
]
}