7.5

CVE-2004-2567

Multiple SQL injection vulnerabilities in ReciPants 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RecipantsRecipants Version1.0
RecipantsRecipants Version1.0.1
RecipantsRecipants Version1.1
RecipantsRecipants Version1.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.21% 0.645
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/11533
Patch
Vendor Advisory
http://securitytracker.com/id?1009984
Patch
http://sourceforge.net/project/shownotes.php?group_id=90737&release_id=234415
Patch
http://www.securityfocus.com/bid/10250
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/16024