René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

94 lines
2.9 KiB
JSON

{
"id": "CVE-2007-4210",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-08-08T02:17:00.000",
"lastModified": "2017-07-29T01:32:46.927",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART Modules, or (3) the gid parameter in a view action in the GALLERY Modules."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en module.php de LANAI (la-nai) CMS 1.2.14 permite a atacantes remotos ejecutar comandos SQL de su elecci\u00f3n a trav\u00e9s del par\u00e1metro (1) mid en una acci\u00f3n faqviewgroup en los M\u00f3dulos FAQ (preguntas frecuentes), el par\u00e1metro (2) cid en M\u00f3dulos EZSHOPINGCART, o el par\u00e1metro (3) gid en una acci\u00f3n view en los M\u00f3dulos GALLERY."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redline_software:lanai_cms:1.2.14:*:*:*:*:*:*:*",
"matchCriteriaId": "B0E757B1-244F-4FA5-850C-D28D5B00AA25"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/2975",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/475447",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25193",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35786",
"source": "cve@mitre.org"
}
]
}