2024-07-14 02:06:08 +00:00

99 lines
2.8 KiB
JSON

{
"id": "CVE-2007-2058",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-04-18T03:19:00.000",
"lastModified": "2017-07-29T01:31:12.487",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Directory traversal vulnerability in Acubix PicoZip 4.02 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the file path in an (1) GZ, (2) TAR, (3) RAR, (4) JAR, or (5) ZIP archive."
},
{
"lang": "es",
"value": "Vulnerabilidad de salto de directorio en PicoZip 4.02 permite a atacantes remotos con la complicidad del usuario sobrescribir ficheros de su elecci\u00f3n mediante secuencias .. (punto punto) en la ruta de ficheros del tipo (1) GZ, (2) TAR, (3) RAR, (4) JAR, o (5) ZIP."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:picozip:picozip:4.02:*:*:*:*:*:*:*",
"matchCriteriaId": "411955D9-694C-48A7-A6AB-B664D593FC1D"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/24868",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.bugtraq.ir/articles/advisory/picozip_directory_traversal/9",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/23471",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1377",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33639",
"source": "cve@mitre.org"
}
]
}