Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf2c-ccw7-485g

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the comtext parameter, in conjunction with crafted comname and comtitle parameters, in a poll action to index.php, related to incorrect input sanitization in base/danneo.function.php.

SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the comtext parameter, in conjunction with crafted comname and comtitle parameters, in a poll action to index.php, related to incorrect input sanitization in base/danneo.function.php.

EPSS

Процентиль: 61%
0.0042
Низкий

Дефекты

CWE-89

Связанные уязвимости

nvd
больше 16 лет назад

SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the comtext parameter, in conjunction with crafted comname and comtitle parameters, in a poll action to index.php, related to incorrect input sanitization in base/danneo.function.php.

EPSS

Процентиль: 61%
0.0042
Низкий

Дефекты

CWE-89