2024-12-08 03:06:42 +00:00

109 lines
3.1 KiB
JSON

{
"id": "CVE-2007-6399",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-12-17T18:46:00.000",
"lastModified": "2024-11-21T00:40:03.803",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action."
},
{
"lang": "es",
"value": "index.php de Flat PHP Board 1.2 y versiones anteriores permite a usuarios remotos autenticados obtener la contrase\u00f1a para la cuenta actual de usuario al leer el valor del par\u00e1metro password en el c\u00f3digo fuente HTML para la p\u00e1gina generada por una acci\u00f3n profile."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"baseScore": 6.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:myupb:flat_php_board:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.2",
"matchCriteriaId": "04695CA6-CE7A-447B-B39D-B1F08DD4199D"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/44118",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/484803/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/26782",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/4705",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/44118",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/484803/100/100/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/26782",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/4705",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}