Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-2010

Опубликовано: 08 июн. 2009
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) thread parameter to messageboard.php, (2) member parameter to profile.php, (3) pid parameter to gallery/index.php, and the (4) fcms_login_id cookie parameter.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:haudenschilt:family_connections_cms:*:*:*:*:*:*:*:*
Версия до 1.9 (включая)
cpe:2.3:a:haudenschilt:family_connections_cms:0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:haudenschilt:family_connections_cms:0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:haudenschilt:family_connections_cms:0.5:*:*:*:*:*:*:*
cpe:2.3:a:haudenschilt:family_connections_cms:0.6:*:*:*:*:*:*:*
cpe:2.3:a:haudenschilt:family_connections_cms:0.8:*:*:*:*:*:*:*
cpe:2.3:a:haudenschilt:family_connections_cms:0.9:*:*:*:*:*:*:*
cpe:2.3:a:haudenschilt:family_connections_cms:1.4:*:*:*:*:*:*:*
cpe:2.3:a:haudenschilt:family_connections_cms:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:haudenschilt:family_connections_cms:1.8.2:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00302
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
почти 4 года назад

Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) thread parameter to messageboard.php, (2) member parameter to profile.php, (3) pid parameter to gallery/index.php, and the (4) fcms_login_id cookie parameter.

EPSS

Процентиль: 53%
0.00302
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-89