Описание
Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:usolved:newsolved:1.1.6:*:*:*:*:*:*:*
EPSS
Процентиль: 46%
0.00233
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
почти 4 года назад
Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.
EPSS
Процентиль: 46%
0.00233
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-89