2024-12-08 03:06:42 +00:00

112 lines
3.0 KiB
JSON

{
"id": "CVE-2009-0301",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-01-27T20:30:05.157",
"lastModified": "2024-11-21T00:59:35.227",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) SaveFile and (2) ExportToXML methods."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de m\u00e9todo inseguro en el control ActiveX FlexCell.Grid (FlexCell.ocx) en FlexCell Grid Control v5.6.9, permite a atacantes remotos crear y sobrescribir archivos de su elecci\u00f3n a trav\u00e9s de los m\u00e9todos (1) SaveFile y (2) ExportToXML."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"baseScore": 6.8,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:grid2000:flexcell_grid_control:5.6.9:*:*:*:*:*:*:*",
"matchCriteriaId": "8ED66658-42A9-4EB2-A7FE-4E7A594B4F2A"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/33664",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/33453",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "https://www.exploit-db.com/exploits/7868",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/33664",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/33453",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit"
]
},
{
"url": "https://www.exploit-db.com/exploits/7868",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}