René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

95 lines
2.9 KiB
JSON

{
"id": "CVE-2008-7085",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-08-26T14:24:16.877",
"lastModified": "2017-09-29T01:33:31.467",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the viewpage action to the default URI, probably index.php, or (2) divid parameter in the schedule action to index.php."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en Maian Greetings v2.0 Basic y Advanced, permite a atacantes remotos ejecutar secuencias de comandos SQL de su elecci\u00f3n a trav\u00e9s de los par\u00e1metros (1) \"id\" en una acci\u00f3n viewpage a la URI por defecto, probablemente index.php, o (2) \"divid\" en una acci\u00f3n schedule a index.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:thehockeystop:hockeystats_online:2.0:*:advanced:*:*:*:*:*",
"matchCriteriaId": "D45D14DD-701E-440E-8759-CD697E3ACF7B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:thehockeystop:hockeystats_online:2.0:*:basic:*:*:*:*:*",
"matchCriteriaId": "F7805DAA-6BCD-4B7C-946C-AD447B2947E1"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/30248",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43852",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/6084",
"source": "cve@mitre.org"
}
]
}