Show plain JSON{"id": "CVE-2006-3332", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false}]}, "published": "2006-06-30T23:05:00.000", "references": [{"url": "http://pridels0.blogspot.com/2006/06/zorum-forum-35-vuln.html", "source": "cve@mitre.org"}, {"url": "http://securitytracker.com/id?1016386", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/18681", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/24372", "source": "cve@mitre.org"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-Other"}]}], "descriptions": [{"lang": "en", "value": "SQL injection vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to execute arbitrary SQL commands via the (1) offset, (2) tid, (3) fromid, (4) sortby, (5) fromfrommethod, and (6) fromfromlist parameters."}, {"lang": "es", "value": "Vulnerabilidad de inyecci\u00f3n SQL en index.php en Zorum Forum v3.5 permite a atacantes remotos ejecutar comandos SQL a trav\u00e9s de los par\u00e1metros (1)offset, (2) tid, (3) fromid, (4) sortby, (5) fromfrommethod, y (6) fromfromlist"}], "lastModified": "2017-07-20T01:32:14.820", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:phpoutsourcing:zorum:3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C2D033F-18B3-49C1-9EF3-347685F12E83"}, {"criteria": "cpe:2.3:a:phpoutsourcing:zorum:3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70AE9137-3FC1-4B5A-B460-D46DF8E041B9"}, {"criteria": "cpe:2.3:a:phpoutsourcing:zorum:3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "907D1B87-2347-4B70-A045-0DDF93662A07"}, {"criteria": "cpe:2.3:a:phpoutsourcing:zorum:3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ACB559F1-D8A6-4265-963C-1265FC7997A4"}, {"criteria": "cpe:2.3:a:phpoutsourcing:zorum:3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EEE0A89A-6DB5-482F-985C-C314DC4D5E28"}, {"criteria": "cpe:2.3:a:phpoutsourcing:zorum:3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7D1D438-86A5-4224-852F-EC1E5DB83DC4"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}