Show plain JSON{"id": "CVE-2007-4261", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2007-08-08T23:17:00.000", "references": [{"url": "http://secunia.com/advisories/26341", "source": "cve@mitre.org"}, {"url": "http://securityreason.com/securityalert/2985", "source": "cve@mitre.org"}, {"url": "http://www.airscanner.com/security/07080601_ezphotosales.htm", "source": "cve@mitre.org"}, {"url": "http://www.informit.com/guides/content.asp?g=security&seqNum=267", "source": "cve@mitre.org"}, {"url": "http://www.informit.com/guides/content.asp?g=security&seqNum=268", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/475678/100/0/threaded", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/25323", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35840", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35841", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/26341", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://securityreason.com/securityalert/2985", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.airscanner.com/security/07080601_ezphotosales.htm", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.informit.com/guides/content.asp?g=security&seqNum=267", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.informit.com/guides/content.asp?g=security&seqNum=268", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/475678/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/25323", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35840", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35841", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-255"}]}], "descriptions": [{"lang": "en", "value": "EZPhotoSales 1.9.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) a file containing cleartext passwords via a direct request for OnlineViewing/data/galleries.txt, or (2) a file containing username hashes and password hashes via a direct request for OnlineViewing/configuration/config.dat/. NOTE: vector 2 can be leveraged for administrative access because authentication does not require knowledge of cleartext values, but instead uses the username hash in the ConfigLogin parameter and the password hash in the ConfigPassword parameter."}, {"lang": "es", "value": "EZPhotoSales 1.9.3 y versiones anteriores almacena informaci\u00f3n confidencial bajo el ra\u00edz del web con control de acceso insuficiente, lo cual permite a atacantes remotos descargar (1) un fichero conteniendo contrase\u00f1as en texto en claro mediante una petici\u00f3n directa de OnlineViewing/data/galleries.txt, \u00f3 (2) un fichero conteniendo res\u00famenes de nombres de usuario o de contrase\u00f1a mediante una petici\u00f3n directa de OnlineViewing/configuration/config.dat/.\r\nNOTA: El vector 2 puede ser utilizado para acceso administrativo dado que la autenticaci\u00f3n no requiere conocimiento de valores en texto en claro, pero en su lugar, utiliza el resumen del nombre de usuario en el par\u00e1metro ConfigLogin y el resumen de la contrase\u00f1a en el par\u00e1metro ConfigPassword."}], "lastModified": "2024-11-21T00:35:10.407", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ez_photo_sales:ez_photo_sales:1.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71EBECDB-13CC-4471-9349-F2E3D1E7A409"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}