Show plain JSON{"id": "CVE-2017-11167", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2017-07-12T13:29:00.237", "references": [{"url": "http://www.03sec.com/3169.shtml", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.03sec.com/3169.shtml", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-94"}]}], "descriptions": [{"lang": "en", "value": "FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager \"Add Site\" action to enter this code after a ', sequence in a domain name, as demonstrated by the ',phpinfo() input value."}, {"lang": "es", "value": "FineCMS 2.1.0 permite que atacantes remotos ejecuten c\u00f3digo PHP arbitrario mediante una acci\u00f3n URL Manager \"Add Site\" action para introducir este c\u00f3digo tras una secuencia ', en un nombre de dominio, tal y como demuestra el valor de entrada ',phpinfo()."}], "lastModified": "2024-11-21T03:07:14.793", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:finecms_project:finecms:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7FBD7CA1-0C29-468D-89D7-35104187D591"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}