Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xj3v-mc9q-x9hh

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO.

SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO.

EPSS

Процентиль: 63%
0.00458
Низкий

Дефекты

CWE-89

Связанные уязвимости

nvd
почти 18 лет назад

SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO.

EPSS

Процентиль: 63%
0.00458
Низкий

Дефекты

CWE-89