« Volver al listado

CVE-2007-1827

Estado: ModificadaMedia (6)—

Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corrupt data files, gain access to private files, and execute arbitrary code via "certain characters."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-1827",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-04-03T00:19:00.000",
  "references": [
    {
      "url": "http://osvdb.org/45396",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/24227",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.attrition.org/pipermail/vim/2007-March/001455.html",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/0720",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=252",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=254",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/45396",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/24227",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.attrition.org/pipermail/vim/2007-March/001455.html",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/0720",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=252",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=254",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corrupt data files, gain access to private files, and execute arbitrary code via \"certain characters.\""
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades no especificadas en el formulario de validación de entrada en web-app.org WebAPP anterior a 0.9.9.6 permite a  usuarios remotos validados corromper archivos de datos, ganar accesos en archivos privados, y ejecutar código de su elección a través de \"ciertos caracteres\"."
    }
  ],
  "lastModified": "2026-06-16T22:38:22.417",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79090F47-9D7C-42F4-A64E-6633A3CF73F0"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA8C727E-412A-4044-8FE9-63C4FD8D4779"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87B45A79-F173-44D6-8737-22DDE3877AE7"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A343A7FD-E5BA-4C84-913B-2B56AFA555FD"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9216F8B4-8B90-4DF0-9135-CFBBBE8E199E"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E7890A9-68D0-4882-9BF0-EE90C32DA554"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "124D5CC6-651A-4C59-975E-D23500DE0EA9"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA59FFEE-6845-4CE3-A7EA-E974165F0688"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9324314-F9CB-4A02-B550-EB8A478BDDB8"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE858A8E-EF70-45CB-8422-2F41B2B6233C"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC102B4E-32FB-4424-8BF9-1E69A95961D4"
            },
            {
              "criteria": "cpe:2.3:a:web-app.org:webapp:0.9.9.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B1DDBEC-988E-44EB-B035-154C61B04DBC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}