René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

95 lines
2.8 KiB
JSON

{
"id": "CVE-2006-4311",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-08-23T19:04:00.000",
"lastModified": "2018-10-17T21:34:30.897",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary PHP code via the folder parameter in multiple files in the plugins directory, as demonstrated by plugins/1_Adressbuch/delete.php."
},
{
"lang": "es",
"value": "Vulnerabilidad de inclusi\u00f3n remota de archivo en Sonium Enterprise Adressbook 0.2 permite a un atacante remoto provocar ejecutar c\u00f3digo PHP de su elecci\u00f3n a trav\u00e9s del par\u00e1meto folder en m\u00faltiples archivos en los directorios pulignsm como se demostr\u00f3 por plugins/1_Adressbuch/delete.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sonium:enterprise_adressbook:0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "B0DC1E2C-DED9-440E-81A2-083D1CF66F25"
}
]
}
]
}
],
"references": [
{
"url": "http://www.bb-pcsecurity.de/Websecurity/342/org/Sonium_Enterprise_Adressbook_Version_0.2_(folder)_RFI.htm",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/443701/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/19597",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3334",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28464",
"source": "cve@mitre.org"
}
]
}