2025-01-26 03:03:52 +00:00

164 lines
4.7 KiB
JSON

{
"id": "CVE-2010-0147",
"sourceIdentifier": "psirt@cisco.com",
"published": "2010-02-23T20:30:00.627",
"lastModified": "2024-11-21T01:11:37.680",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyecci\u00f3n SQL en el Management Center para Cisco Security Agents v5.1 anterior a v5.1.0.117, v5.2 anterior a v5.2.0.296, y v6.0 anterior a v6.0.1.132, permite a usuarios autenticados remotamente ejecutar comandos SQL de su elecci\u00f3n a trav\u00e9s de vectores sin especificar."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"baseScore": 6.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:security_agent:5.1:*:*:*:*:*:*:*",
"matchCriteriaId": "F6DD0915-7671-42CD-8DF3-0B685389C528"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:security_agent:5.2:*:*:*:*:*:*:*",
"matchCriteriaId": "734B38F1-6FEC-4A94-B1C9-D076750A133F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:security_agent:6.0:*:*:*:*:*:*:*",
"matchCriteriaId": "8805C68E-E152-4089-B74C-1B7703ECC064"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/62444",
"source": "psirt@cisco.com"
},
{
"url": "http://secunia.com/advisories/38619",
"source": "psirt@cisco.com",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtml",
"source": "psirt@cisco.com",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/38272",
"source": "psirt@cisco.com"
},
{
"url": "http://www.securitytracker.com/id?1023606",
"source": "psirt@cisco.com"
},
{
"url": "http://www.vupen.com/english/advisories/2010/0416",
"source": "psirt@cisco.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/56346",
"source": "psirt@cisco.com"
},
{
"url": "http://osvdb.org/62444",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/38619",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtml",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/38272",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1023606",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/0416",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/56346",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}