« Volver al listado

CVE-2020-35743

Estado: ModificadaAlta (7.6)—

HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-35743",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "HGiga",
          "product": "MailSherlock MSR45/SSR45",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "120",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "iSherlock-user-4.5"
          ]
        },
        {
          "vendor": "HGiga",
          "product": "MailSherlock MSR45/SSR45",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "133",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "iSherlock-antispam-4.5"
          ]
        }
      ]
    }
  ],
  "published": "2020-12-31T08:15:13.847",
  "references": [
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-4262-03785-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-4262-03785-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages."
    },
    {
      "lang": "es",
      "value": "HGiga MailSherlock contiene un fallo de inyección SQL. Unos atacantes pueden inyectar y ejecutar comandos SQL en un parámetro URL de páginas CGI específicas."
    }
  ],
  "lastModified": "2026-06-17T03:14:13.797",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hgiga:msr45_isherlock-antispam:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E5B5E25-BC65-49E2-9865-9BC9A4DE98F0",
              "versionEndExcluding": "4.5-133"
            },
            {
              "criteria": "cpe:2.3:a:hgiga:msr45_isherlock-user:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F203F7FA-9E30-49AD-956C-5E893B1264A4",
              "versionEndExcluding": "4.5-120"
            },
            {
              "criteria": "cpe:2.3:a:hgiga:ssr45_isherlock-antispam:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAAA3F24-7821-4F5A-A64E-EEA30B269DD2",
              "versionEndExcluding": "4.5-133"
            },
            {
              "criteria": "cpe:2.3:a:hgiga:ssr45_isherlock-user:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE0FEDEB-2C43-4C45-800A-9323146DC214",
              "versionEndExcluding": "4.5-120"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "twcert@cert.org.tw"
}