Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h98c-hq83-wq3c

Опубликовано: 25 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).

Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).

EPSS

Процентиль: 78%
0.01177
Низкий

7.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
nvd
около 3 лет назад

Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).

EPSS

Процентиль: 78%
0.01177
Низкий

7.2 High

CVSS3

Дефекты

CWE-89