CVE-2007-5090
https://notcve.org/view.php?id=CVE-2007-5090
Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt data via unspecified vectors. Vulnerabilidad sin especificar en el IBM Rational ClearQuest (CQ), cuando se utilizan las bases de datos Microsoft SQL Server o IBM DB2, permite a atacantes remotos corromper los datos a través de vectores sin especificar. • http://osvdb.org/40598 http://secunia.com/advisories/26899 http://www-1.ibm.com/support/docview.wss?uid=swg21268116 http://www.securityfocus.com/bid/25810 http://www.securitytracker.com/id?1018735 http://www.vupen.com/english/advisories/2007/3264 https://exchange.xforce.ibmcloud.com/vulnerabilities/36771 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2007-4368 – IBM Rational ClearQuest - Web Authentication Bypass / SQL Injection
https://notcve.org/view.php?id=CVE-2007-4368
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command. Una vulnerabilidad de inyección SQL en /main en IBM Rational ClearQuest (CQ) Web versiones 7.0.0.0.0-IFIX02 y 7.0.0.0.1, permite a atacantes remotos ejecutar comandos SQL arbitrarios por medio del parámetro username en un comando GenerateMainFrame. • https://www.exploit-db.com/exploits/4286 http://osvdb.org/36478 http://securityreason.com/securityalert/3012 http://www.securityfocus.com/archive/1/476475/100/0/threaded http://www.securityfocus.com/bid/25324 http://www.securitytracker.com/id?1018569 https://exchange.xforce.ibmcloud.com/vulnerabilities/36012 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2007-1468
https://notcve.org/view.php?id=CVE-2007-1468
Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el IBM Rational ClearQuest (CQ) Web 7.0.0.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante un adjunto en la entrada de log por defecto. • http://osvdb.org/34346 http://secunia.com/advisories/24523 http://securityreason.com/securityalert/2442 http://www.securityfocus.com/archive/1/462919/100/0/threaded http://www.securityfocus.com/bid/22981 http://www.securitytracker.com/id?1017786 http://www.vupen.com/english/advisories/2007/1036 https://exchange.xforce.ibmcloud.com/vulnerabilities/33001 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •