René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

83 lines
2.4 KiB
JSON

{
"id": "CVE-2008-0233",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-01-11T02:46:00.000",
"lastModified": "2017-09-29T01:30:10.770",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg."
},
{
"lang": "es",
"value": "Vulnerabilidad de subida de fichero no restringida en Zero CMS 1.0 Alpha y anteriores permite a atacantes remotos evitar las restricciones de acceso planeadas y ejecutar ficheros de su elecci\u00f3n subiendo un fichero de avatar con tipo de contenido (Content-Type) como image/jpeg."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:zero_cms:zero_cms:1.0_alpha:*:*:*:*:*:*:*",
"matchCriteriaId": "E05AC519-6859-4308-BEF1-23D8666472A2"
}
]
}
]
}
],
"references": [
{
"url": "http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/4864",
"source": "cve@mitre.org"
}
]
}