CVE-2007-5463
Estado: ModificadaMedia (5)—
ideal_process.php in the iDEAL payment module in ViArt Shop 3.3 beta and earlier might allow remote attackers to obtain the pathname for certificate and key files via an "iDEAL transaction", possibly involving fopen error messages for nonexistent files, a different issue than CVE-2007-5364. NOTE: this can be leveraged for reading certificate or key files if an installation places these files under the web document root.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.98%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- http://osvdb.org/40151
- http://secunia.com/advisories/27199
- http://securityreason.com/securityalert/3233
- http://www.securityfocus.com/archive/1/481978/100/0/threaded
- http://www.securityfocus.com/bid/25998
- http://www.viart.com/ideal_process_script_fix_for_release_32_and_33_beta.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37048
- http://osvdb.org/40151
- http://secunia.com/advisories/27199
- http://securityreason.com/securityalert/3233
- http://www.securityfocus.com/archive/1/481978/100/0/threaded
- http://www.securityfocus.com/bid/25998
- http://www.viart.com/ideal_process_script_fix_for_release_32_and_33_beta.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37048
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-5463",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-10-15T22:17:00.000",
"references": [
{
"url": "http://osvdb.org/40151",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/27199",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3233",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/481978/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25998",
"source": "cve@mitre.org"
},
{
"url": "http://www.viart.com/ideal_process_script_fix_for_release_32_and_33_beta.html",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/37048",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/40151",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/27199",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3233",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/481978/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/25998",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.viart.com/ideal_process_script_fix_for_release_32_and_33_beta.html",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/37048",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ideal_process.php in the iDEAL payment module in ViArt Shop 3.3 beta and earlier might allow remote attackers to obtain the pathname for certificate and key files via an \"iDEAL transaction\", possibly involving fopen error messages for nonexistent files, a different issue than CVE-2007-5364. NOTE: this can be leveraged for reading certificate or key files if an installation places these files under the web document root."
},
{
"lang": "es",
"value": "ideal_process.php en el módulo de pago iDEAL de ViArt Shop 3.3 beta y versiones anteriores podría permitir a atacantes remotos obtener el nombre de ruta de un certificado y ficheros de clave mediante una \"transacción iDEAL\", posiblemente involucrando mensajes de error fopen para ficheros no existentes, asunto diferente de CVE-2007-5364.\r\nNOTA: esto podría ser utilizado para leer certificados o ficheros de clave si una instalación sitúa estos ficheros bajo la raíz de documentos web."
}
],
"lastModified": "2026-06-16T22:46:12.460",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:viart:shop:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC0F7B7E-49CF-4E38-B71B-9ADEB6B2D4D0",
"versionEndIncluding": "3.3_beta"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}