Описание
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the search feature and the (3) SearchContentClassAttributeID parameter to the advancedsearch feature.
Ссылки
- Patch
- Patch
- PatchVendor Advisory
- Vendor Advisory
- Patch
- Patch
- PatchVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:ez:ez_publish:3.7.0:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.1:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.2:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.3:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.4:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.5:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.6:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.7:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.8:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.9:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.10:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.11:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.12:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:4.2.0:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.0133
Низкий
7.5 High
CVSS2
Дефекты
CWE-89
Связанные уязвимости
debian
около 16 лет назад
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2 ...
github
больше 4 лет назад
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the search feature and the (3) SearchContentClassAttributeID parameter to the advancedsearch feature.
EPSS
Процентиль: 68%
0.0133
Низкий
7.5 High
CVSS2
Дефекты
CWE-89