Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-69vw-jfq7-935g

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

PyWebDAV SQL Injection vulnerability

Multiple SQL injection vulnerabilities in the get_userinfo method in the MySQLAuthHandler class in DAVServer/mysqlauth.py in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.

Пакеты

Наименование

pywebdav

pip
Затронутые версииВерсия исправления

< 0.9.4.1

0.9.4.1

EPSS

Процентиль: 77%
0.01021
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

ubuntu
почти 15 лет назад

Multiple SQL injection vulnerabilities in the get_userinfo method in the MySQLAuthHandler class in DAVServer/mysqlauth.py in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.

nvd
почти 15 лет назад

Multiple SQL injection vulnerabilities in the get_userinfo method in the MySQLAuthHandler class in DAVServer/mysqlauth.py in PyWebDAV before 0.9.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) pw argument. NOTE: some of these details are obtained from third party information.

debian
почти 15 лет назад

Multiple SQL injection vulnerabilities in the get_userinfo method in t ...

EPSS

Процентиль: 77%
0.01021
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-89