CVE-2017-2163
Published May 12, 2017
Last updated 7 years ago
Overview
- Description
- Directory traversal vulnerability in SOY CMS Ver.1.8.1 to Ver.1.8.12 allows authenticated attackers to read arbitrary files via shop_id.
- Source
- vultures@jpcert.or.jp
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-22
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "82D060DF-DF3C-4CE9-BC3B-9CC1408A04EC" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "116BC2BF-44A6-409C-A22F-9361386D60F7" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28692E0A-F41B-41E6-8339-566B2BA944E0" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "90E1A3CF-2671-4E1A-9331-574B923D2DDF" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "538E250C-5FD5-45C8-A527-2C22BA748ED6" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0892384B-4AE4-43E7-BDCC-00F96362A1DC" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E9AD215-0223-4452-B859-0F79F1A55D86" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF504454-B3E8-494A-86D8-AB68A58E0BE1" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F7E980B-9B25-430C-A8FD-EFC59DEE1E8C" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4DB22671-D08D-49AF-9D97-EE1435DA9F33" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D4E627BF-C070-4076-8582-D3A7E2B9DABD" }, { "criteria": "cpe:2.3:a:n-i-agroinformatics:soy_cms:1.8.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2F72D69-24C8-42CF-851E-7BAF5B2612AC" } ], "operator": "OR" } ] } ]