René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

89 lines
2.8 KiB
JSON

{
"id": "CVE-2009-2439",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-07-13T14:30:00.297",
"lastModified": "2010-02-13T05:00:00.000",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party; it is not associated with alibaba.com or the Alibaba Group."
},
{
"lang": "es",
"value": "Varias vulnerabilidades de inyecci\u00f3n SQL en Web Development House Alibaba Clone, permite a los atacantes remotos ejecutar comandos SQL arbitrarios por medio del (1) par\u00e1metro IndustryID en category.php y el (2) par\u00e1metro SellerID en supplier/view_contact_details.php. NOTA: este es un producto que fue desarrollado por un tercero; no est\u00e1 asociado con alibaba.com o el Grupo Alibaba."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:web_development_house:alibaba_clone:*:*:*:*:*:*:*:*",
"matchCriteriaId": "40C8CCA5-B271-43B5-AA90-CD5D59DB527C"
}
]
}
]
}
],
"references": [
{
"url": "http://packetstormsecurity.org/0907-exploits/alibabaclone-sql.txt",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.vupen.com/english/advisories/2009/1838",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
}
]
}