Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-3076

Опубликовано: 14 окт. 2010
Источник: ubuntu
Приоритет: high
CVSS2: 7.5

Описание

The filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via the username parameter to the admin login page.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

jaunty

ignored

end of life
karmic

ignored

end of life
lucid

released

0.4.7-3+lenny1build0.10.04.1
maverick

ignored

end of life
natty

not-affected

0.4.7-5
oneiric

not-affected

upstream

released

0.4.7-5

Показывать по

Ссылки на источники

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 16 лет назад

The filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via the username parameter to the admin login page.

debian
почти 16 лет назад

The filter function in php/src/include.php in Simple Management for BI ...

github
около 4 лет назад

The filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via the username parameter to the admin login page.

7.5 High

CVSS2