Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-8979

Опубликовано: 21 фев. 2019
Источник: debian
EPSS Низкий

Описание

Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libkohana2-phpremovedpackage
libkohana2-phpnot-affectedjessiepackage

Примечания

  • https://github.com/huzr2018/orderby_SQLi/tree/master/kohana

  • https://github.com/koseven/koseven/issues/323

EPSS

Процентиль: 87%
0.03204
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.

CVSS3: 9.8
nvd
больше 7 лет назад

Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.

CVSS3: 9.8
github
больше 4 лет назад

Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.

EPSS

Процентиль: 87%
0.03204
Низкий