René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

87 lines
2.6 KiB
JSON

{
"id": "CVE-2009-2356",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-07-07T23:30:00.360",
"lastModified": "2018-10-10T19:39:49.867",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7, when PostgreSQL is used, might allow remote attackers to execute arbitrary code via input to the (1) POP3, (2) SMTP, or (3) web component that triggers a long SQL query."
},
{
"lang": "es",
"value": "Desbordamiento m\u00faltiple basado en pila de la funci\u00f3n pgsqlQuery en NullLogic Groupware v1.2.7, cuando PostgreSQL es usado, quiz\u00e1s permita a los atacantes remotos ejecutar c\u00f3digo a su elecci\u00f3n a trav\u00e9s (1) POP3, (2) SMTP, o (3) componente web que provoca una petici\u00f3n larga SQL."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 9.3
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.6,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:dan_cahill:nulllogic_groupware:1.2.7:*:*:*:*:*:*:*",
"matchCriteriaId": "2C7AD5C6-C4CF-4F21-9ED1-CFAF8859C384"
}
]
}
]
}
],
"references": [
{
"url": "http://www.nth-dimension.org.uk/utils/get.php?downloadsid=55",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/504737/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2009/1817",
"source": "cve@mitre.org"
}
]
}