7.5

CVE-2004-2551

Exploit
Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in export_data.asp, (4) the sys_analgroup parameter in manageanalgrouppreference.asp, (5) the sys_asset_id parameter in quickinfoassetrequests.asp, (6) the sys_eusername parameter in quickinfoenduserrequests.asp, and the sys_request_id parameter in (7) requestauditlog.asp, (8) requestcommentsenduser.asp, (9) selectrequestapplytemplate.asp, and (10) selectrequestlink.asp, resulting in an ability to create a new HelpBox user account and read, modify, or delete data from the backend database.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Layton TechnologyHelpbox Version3.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.29% 0.81
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/12118
Patch
Vendor Advisory
http://www.osvdb.org/8170
Patch
http://www.osvdb.org/8171
Patch
http://www.osvdb.org/8172
Patch
http://www.osvdb.org/8173
Patch
http://www.osvdb.org/8174
Patch
http://www.osvdb.org/8175
Patch
http://www.osvdb.org/8176
Patch
http://www.osvdb.org/8177
Patch
http://www.osvdb.org/8178
Patch
http://www.osvdb.org/8179
Patch
http://www.securiteam.com/windowsntfocus/5VP0S0ADFW.html
http://www.securityfocus.com/bid/10776
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/16772
https://exchange.xforce.ibmcloud.com/vulnerabilities/16774