2024-12-08 03:06:42 +00:00

109 lines
3.2 KiB
JSON

{
"id": "CVE-2007-1895",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-04-09T20:19:00.000",
"lastModified": "2024-11-21T00:29:24.630",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, allows remote attackers to execute arbitrary PHP code via an ftp URL in a my_ms[root] cookie, a different vector than CVE-2007-0491 and CVE-2006-4630."
},
{
"lang": "es",
"value": "Vulnerabilidad de inclusi\u00f3n remota de archivo en PHP en chat.php de Sky GUNNING MySpeach 3.0.7 y anteriores, cuando se usa con PHP 5, permite a atacantes remotos ejecutar c\u00f3digo PHP de su elecci\u00f3n mediante un URL de tipo ftp en la cookie my_ms[root], un vector distinto de CVE-2007-0491 y CVE-2006-4630."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"baseScore": 6.8,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sky_gunning:myspeach:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.0.7",
"matchCriteriaId": "20FC35AB-D1BA-463B-A7F0-9FD42F05F982"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/34145",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/24760",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1261",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/3657",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/34145",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/24760",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1261",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/3657",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}