René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

83 lines
2.5 KiB
JSON

{
"id": "CVE-2009-2080",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-06-16T19:30:00.327",
"lastModified": "2017-09-29T01:34:42.733",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator's password via the id parameter in an editop action."
},
{
"lang": "es",
"value": "admin.php en MRCGIGUY The Ticket System v2.0, no restringe adecuadamente el acceso, lo que permite a atacantes remotos (1) obtener informaci\u00f3n sobre la configuraci\u00f3n a trav\u00e9s de una acci\u00f3n \"editconfig\" o (2) modificar la contrase\u00f1a de administrador a trav\u00e9s del par\u00e1metro \"id\" en una acci\u00f3n \"editop\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mrcgiguy:the_ticket_system:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "3AF7C1FB-07D9-49C2-B6F3-0A606AE180BA"
}
]
}
]
}
],
"references": [
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51029",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/8917",
"source": "cve@mitre.org"
}
]
}