Логотип exploitDog
bind:CVE-2019-12385
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-12385

Количество 4

Количество 4

ubuntu логотип

CVE-2019-12385

больше 6 лет назад

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-12385

больше 6 лет назад

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-12385

больше 6 лет назад

An issue was discovered in Ampache through 3.9.1. The search engine is ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-p72w-3684-2crg

больше 3 лет назад

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-12385

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-12385

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-12385

An issue was discovered in Ampache through 3.9.1. The search engine is ...

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
github логотип
GHSA-p72w-3684-2crg

An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу