2024-11-22 11:14:00 +00:00

135 lines
4.0 KiB
JSON

{
"id": "CVE-2009-4606",
"sourceIdentifier": "cve@mitre.org",
"published": "2010-01-13T11:30:00.373",
"lastModified": "2024-11-21T01:10:02.057",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command."
},
{
"lang": "es",
"value": "South River Technologies WebDrive v9.02 build 2232 instala el servicio de disco remoto sin un descriptor de seguridad, lo que permite a usuarios locales (1) parar el servicio a trav\u00e9s del comando \"stop\", (2) ejecutar comandos arbitrarios como SYSTEM mediante el uso del comando \"config\" para modificar la variable \"binPatch\", o (3) reiniciar el servicio a trav\u00e9s del comando \"Start\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"baseScore": 7.2,
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 3.9,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:south_river_technologies:webdrive:9.02:build_2232:*:*:*:*:*:*",
"matchCriteriaId": "FAABF1E0-FCA2-4206-8C33-CF8ED8E7EBAF"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/59080",
"source": "cve@mitre.org"
},
{
"url": "http://retrogod.altervista.org/9sg_south_river_priv.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/37083",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/archive/1/507323/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2009/2994",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53885",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/59080",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://retrogod.altervista.org/9sg_south_river_priv.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/37083",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/archive/1/507323/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2009/2994",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53885",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}