« Volver al listado

CVE-2012-0263

Estado: ModificadaMedia (4)—

monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error messages that are triggered by (1) a malformed hoststatustypes parameter to status/service/all or (2) a crafted request to config.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-0263",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-12-31T20:55:15.073",
  "references": [
    {
      "url": "http://seclists.org/fulldisclosure/2012/Jan/62",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/47344",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ekelow.se/file_uploads/Advisories/ekelow-aid-2012-01.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.op5.com/news/support-news/fixed-vulnerabilities-op5-monitor-op5-appliance/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/78067",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.op5.com/view.php?id=5094",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2012/Jan/62",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/47344",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ekelow.se/file_uploads/Advisories/ekelow-aid-2012-01.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.op5.com/news/support-news/fixed-vulnerabilities-op5-monitor-op5-appliance/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/78067",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.op5.com/view.php?id=5094",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error messages that are triggered by (1) a malformed hoststatustypes parameter to status/service/all or (2) a crafted request to config."
    },
    {
      "lang": "es",
      "value": "monitor / index.php en el Monitor  y Appliance de  op5 anteriores a 5.5.1 permite a usuarios remotos autenticados  obtener información confidencial, como bases de datos y las credenciales del usuario a través de los mensajes de error que se desencadenan por (1) un parámetro  hoststatustypes malformado en  estado/servicio/ todos o (2) una solicitud manipulada en las configuraciones."
    }
  ],
  "lastModified": "2026-06-16T23:37:00.677",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:op5:monitor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B57AA6A1-CF28-46DC-80FA-67F1023933EF",
              "versionEndIncluding": "5.5.0"
            },
            {
              "criteria": "cpe:2.3:a:op5:monitor:5.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5249E2B6-4B2B-4A4D-9C39-8362B422B0E5"
            },
            {
              "criteria": "cpe:2.3:a:op5:monitor:5.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "108F8953-B90D-4341-8AD5-39E94F7F320B"
            },
            {
              "criteria": "cpe:2.3:a:op5:monitor:5.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14C73510-4999-4C96-9705-59274F97BA77"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}