Описание
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| spotweb | removed | package | ||
| spotweb | no-dsa | buster | package | |
| spotweb | no-dsa | stretch | package |
Примечания
https://github.com/spotweb/spotweb/issues/629
https://github.com/spotweb/spotweb/commit/fefb39ad143caad021ad496427617db79c42aff2
https://github.com/spotweb/spotweb/commit/25c1f89f0202af5d5d224b906ff9d9313f017aa6
When fixing the issue make sure to apply the complete fix for CVE-2020-35545
and not open CVE-2021-3286. Cf.
https://github.com/spotweb/spotweb/issues/653
EPSS
Процентиль: 92%
0.0841
Низкий
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 5 лет назад
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
CVSS3: 9.8
nvd
около 5 лет назад
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
github
больше 3 лет назад
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
EPSS
Процентиль: 92%
0.0841
Низкий