René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

100 lines
2.8 KiB
JSON

{
"id": "CVE-2006-3238",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-06-27T10:05:00.000",
"lastModified": "2018-10-18T16:46:22.987",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in VBZooM 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) MemberID parameter to rank.php, and the (2) QuranID parameter to lng.php."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en VBZooM v.1.0 y anteriores permiten a usuarios autenticados en remoto ejecutar comandos SQL de su elecci\u00f3n mediante (1) el par\u00e1metro MemberID de rank.php y (2) el par\u00e1metro QuranID de lng.php.\r\n"
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:vbzoom:vbzoom:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.00",
"matchCriteriaId": "251C5128-B1E2-466F-91BC-8F01EA1C9A44"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/1149",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/437651/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/437658/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/18497",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2468",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27294",
"source": "cve@mitre.org"
}
]
}