René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

79 lines
2.5 KiB
JSON

{
"id": "CVE-2006-4582",
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com",
"published": "2006-12-31T05:00:00.000",
"lastModified": "2017-07-20T01:33:11.557",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting arbitrary users via the id parameter in a deleteuser action in users.php."
},
{
"lang": "es",
"value": "Vulnerabilidad en la falsificaci\u00f3n de petici\u00f3n en sitios cruzados (CSRF) en el Address Book 1.04e permite a atacantes remotos la realizaci\u00f3n de acciones no autorizadas, como otros usuarios, mediante vectores sin especificar, como lo demostrado mediante el borrado de usuarios de nuestra elecci\u00f3n a trav\u00e9s del par\u00e1metro id en la acci\u00f3n deleteuser en el users.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:the_address_book:the_address_book:1.04e:*:*:*:*:*:*:*",
"matchCriteriaId": "987F84E0-1A6B-484B-B973-9AE2E3ADB435"
}
]
}
]
}
],
"references": [
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/31251",
"source": "PSIRT-CNA@flexerasoftware.com"
}
]
}