Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-2123

Опубликовано: 19 июн. 2009
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable through login.php; and the (3) id parameter to (b) show_bug.php and (c) show_activity.php. NOTE: it was later reported that vector 3c also affects 1.2.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elvinbts:elvinbts:1.2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.00338
Низкий

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
почти 4 года назад

Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable through login.php; and the (3) id parameter to (b) show_bug.php and (c) show_activity.php. NOTE: it was later reported that vector 3c also affects 1.2.2.

EPSS

Процентиль: 56%
0.00338
Низкий

7.5 High

CVSS2

Дефекты

CWE-89