Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-0347

Опубликовано: 29 янв. 2007
Источник: debian
EPSS Низкий

Описание

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cvstracfixed2.0.1-1package
cvstracnot-affectedetchpackage
cvstracnot-affectedsargepackage

Примечания

  • the vulnerable code can't be found on other places in 1.1.5 and also similar things

  • are done like using %q instead of %s for user supplied data

EPSS

Процентиль: 85%
0.02508
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.

nvd
больше 18 лет назад

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.

github
больше 3 лет назад

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.

EPSS

Процентиль: 85%
0.02508
Низкий