Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95q2-rgwr-x33j

Опубликовано: 01 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vulnerable parameter. Due to the stacked query support, complex SQL commands could be crafted and injected into the vulnerable parameter and using a sleep based inferential SQL injection it was possible to extract data from the database.

The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vulnerable parameter. Due to the stacked query support, complex SQL commands could be crafted and injected into the vulnerable parameter and using a sleep based inferential SQL injection it was possible to extract data from the database.

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.6
nvd
больше 2 лет назад

The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vulnerable parameter. Due to the stacked query support, complex SQL commands could be crafted and injected into the vulnerable parameter and using a sleep based inferential SQL injection it was possible to extract data from the database.

CVSS3: 9.8
redos
около 2 лет назад

Множественные уязвимости python-pillow

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Дефекты

CWE-89