René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

91 lines
3.0 KiB
JSON

{
"id": "CVE-2007-5223",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-10-05T00:17:00.000",
"lastModified": "2018-10-15T21:41:19.147",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple unspecified vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to include local files and have other unspecified impact, related to incorrect input validation or other defects involving (1) admin/backupstart.php, (2) a .sql filename under admin/admin/dump/, (3) a .sql filename in the fl parameter to admin/downloadbackup.php, and (4) a .. (dot dot) in the fl parameter to admin/downloadbackup.php."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades no espec\u00edficas en AlstraSoft Affiliate Network Pro permite a atacantes remotos incluir archivos locales y tener otro impacto no especificado, relacionado con la validaci\u00f3n de entrada incorrecta u otros defectos afectando a 1) admin/backupstart.php, (2) un nombre de archivo .sql bajo admin/admin/dump/, (3) un nombre de archivo .sql en el par\u00e1metro fl en admin/downloadbackup.php, y (4) una secuencia .. (punto punto) en el par\u00e1metro fl en admin/downloadbackup.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:alstrasoft:affiliate_network_pro:8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "C93CC628-D066-42C8-9662-666BDE7B5BBF"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/3191",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/481206/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25882",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3344",
"source": "cve@mitre.org"
}
]
}