Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4v38-rxj3-wf34

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074.

SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074.

EPSS

Процентиль: 56%
0.00338
Низкий

Дефекты

CWE-89

Связанные уязвимости

nvd
больше 16 лет назад

SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074.

EPSS

Процентиль: 56%
0.00338
Низкий

Дефекты

CWE-89