Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9xh9-9f8q-v4jc

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.

EPSS

Процентиль: 85%
0.02508
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.

nvd
больше 18 лет назад

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.

debian
больше 18 лет назад

The is_eow function in format.c in CVSTrac before 2.0.1 does not prope ...

EPSS

Процентиль: 85%
0.02508
Низкий