René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

79 lines
2.5 KiB
JSON

{
"id": "CVE-2006-6699",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-12-23T01:28:00.000",
"lastModified": "2018-10-17T21:49:27.567",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple CRLF injection vulnerabilities in Oracle Portal 9.0.2 and possibly other versions allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter to (1) calendarDialog.jsp or (2) fred.jsp. NOTE: the calendar.jsp vector is covered by CVE-2006-6697."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n SRLF en Oracle Portal 9.0.2 y posiblemente otras versiones permiten a un atacante remoto inyectar cabeceras HTTP de su elecci\u00f3n y conducir respuestas HTTP diviendo los ataques a trav\u00e9s de secuencias CRLF en el par\u00e1metro enc a (1) calendarDialog.jsp o (2) fred.jsp. NOTA: el vector calendar.jsp est\u00e1 cubierto por CVE-2006-6697."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:oracle:application_server_portal:9.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "15B503FB-F1E6-4A2D-BD4C-1BEE89DE1B53"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/archive/1/455106/100/0/threaded",
"source": "cve@mitre.org"
}
]
}