Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf4f-3xcp-f4gh

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. NOTE: this can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.

SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. NOTE: this can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.

EPSS

Процентиль: 76%
0.00938
Низкий

Дефекты

CWE-89

Связанные уязвимости

nvd
больше 16 лет назад

SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. NOTE: this can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.

EPSS

Процентиль: 76%
0.00938
Низкий

Дефекты

CWE-89