Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2012-1506

почти 12 лет назад

SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from third party information.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2012-1506

почти 12 лет назад

SQL injection vulnerability in the updateStatus function in lib/models ...

CVSS2: 6.5
EPSS: Низкий
github логотип

GHSA-h44f-xp3m-jxrx

больше 4 лет назад

SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-1506

SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from third party information.

CVSS2: 6.5
1%
Низкий
почти 12 лет назад
debian логотип
CVE-2012-1506

SQL injection vulnerability in the updateStatus function in lib/models ...

CVSS2: 6.5
1%
Низкий
почти 12 лет назад
github логотип
GHSA-h44f-xp3m-jxrx

SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу