« Volver al listado

CVE-2008-0701

Estado: ModificadaMedia (5)—

ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-0701",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-02-12T01:00:00.000",
  "references": [
    {
      "url": "http://jira.magnolia.info/browse/MAGNOLIA-2021",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28745",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?release_id=573088",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/27608",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jira.magnolia.info/browse/MAGNOLIA-2021",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28745",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?release_id=573088",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/27608",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content."
    },
    {
      "lang": "es",
      "value": "ActivationHandler en Magnolia CE 3.5.x antes de 3.5.4. No comprueba permisos mientras importa, lo que permite a atacantes remotos tener un impacto desconocido a través de la activación de un nuevo elemento, que posiblemente implique un nuevo contenido de su elección."
    }
  ],
  "lastModified": "2026-06-16T22:50:10.107",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:magnolia:ce:3.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBC1BDFD-6FFC-403C-A77C-9932EB33B091"
            },
            {
              "criteria": "cpe:2.3:a:magnolia:ce:3.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "563C5080-4137-4979-A020-95F2A24A7314"
            },
            {
              "criteria": "cpe:2.3:a:magnolia:ce:3.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F7CA68C-354D-4816-8EE9-3051FCF9E8E8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}