Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-45255

Опубликовано: 21 дек. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:video_sharing_website_project:video_sharing_website:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00263
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
около 4 лет назад

The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed.

EPSS

Процентиль: 49%
0.00263
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-89