René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

87 lines
2.9 KiB
JSON

{
"id": "CVE-2006-6486",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-12-12T20:28:00.000",
"lastModified": "2018-10-17T21:48:20.520",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "SQL injection vulnerability in EasyPage allows remote attackers to execute arbitrary SQL commands via unspecified vectors in sptrees/default.aspx, possibly involving the docId parameter. NOTE: this issue appears to have been disputed by a third party researcher, stating that SQL injection is not possible. However, insufficient details were provided to evaluate the dispute."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyecci\u00f3n SQL en EasyPage permite a atacantes remotos ejecutar comandos SQL de su elecci\u00f3n mediante vectores sin especificar en el sptrees/default.aspx, posiblemente involucrando el par\u00e1metro docId. NOTA: esta vulnerabilidad parece haber sido impugnada por investigadores terceros, estableciendo que inyecciones de SQL no son posibles. Sin embargo, no han sido proporcionados suficientes detalles para la evaluaci\u00f3n de la impugnaci\u00f3n.\r\n"
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:easypage:easypage:*:*:*:*:*:*:*:*",
"matchCriteriaId": "38B57BB9-C403-401C-AD84-5B3F4E04A34C"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/archive/1/453575/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/453586/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30755",
"source": "cve@mitre.org"
}
]
}