Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-12385

Опубликовано: 22 авг. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ampache:ampache:*:*:*:*:*:*:*:*
Версия до 3.9.1 (включая)

EPSS

Процентиль: 72%
0.00703
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 6 лет назад

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.

CVSS3: 8.8
debian
больше 6 лет назад

An issue was discovered in Ampache through 3.9.1. The search engine is ...

CVSS3: 8.8
github
больше 3 лет назад

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.

EPSS

Процентиль: 72%
0.00703
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89