Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9235

Опубликовано: 03 дек. 2014
Источник: debian
EPSS Низкий

Описание

Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zophremovedpackage

Примечания

  • http://seclists.org/fulldisclosure/2014/Nov/45

  • https://github.com/jeroenrnl/zoph/issues/59

  • The SQL injection and XSS claims appear to be mostly unfounded.

EPSS

Процентиль: 73%
0.00748
Низкий

Связанные уязвимости

ubuntu
около 11 лет назад

Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.

nvd
около 11 лет назад

Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.

github
больше 3 лет назад

Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.

EPSS

Процентиль: 73%
0.00748
Низкий