René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

105 lines
3.2 KiB
JSON

{
"id": "CVE-2009-4367",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-12-21T16:30:00.593",
"lastModified": "2018-10-10T19:49:07.617",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The Staging Webservice (\"sitecore modules/staging/service/api.asmx\") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request."
},
{
"lang": "es",
"value": "Staging Webservice (\"sitecore modules/staging/service/api.asmx\") en Sitecore Staging Module v5.4.0 rev.080625 y anteriores permite a atacantes remotos saltar la autenticaci\u00f3n y (1) subir ficheros, (2) bajar ficheros, (3) listar directorios, y (4) limpiar la cach\u00e9 del servidor mediante peticiones SOAP modificas con valores \"Username\" y \"Password\" de su elecci\u00f3n, posiblemente relacionado con una petici\u00f3n directa."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sitecore:staging_module:*:080625:*:*:*:*:*:*",
"versionEndIncluding": "5.4.0",
"matchCriteriaId": "CE7E318B-E8F9-4C7C-AA94-37CBFE146882"
}
]
}
]
}
],
"references": [
{
"url": "http://www.exploit-db.com/exploits/10513",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.securityfocus.com/archive/1/508529/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/37388",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54881",
"source": "cve@mitre.org"
},
{
"url": "https://www.sec-consult.com/files/20091217-0_sitecore_StagingModule_1.0.txt",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
}
]
}