7.5

CVE-2005-3074

SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.

Data is provided by the National Vulnerability Database (NVD)
RsyslogRsyslogd Version <= 1.0.1_stable
RsyslogRsyslogd Version <= 1.10.1_development
RsyslogRsyslogd Version0.8.0_stable
RsyslogRsyslogd Version0.8.1_stable
RsyslogRsyslogd Version0.8.2_stable
RsyslogRsyslogd Version0.8.3_stable
RsyslogRsyslogd Version0.8.4_stable
RsyslogRsyslogd Version0.9.0_stable
RsyslogRsyslogd Version0.9.1_stable
RsyslogRsyslogd Version0.9.2_stable
RsyslogRsyslogd Version0.9.3_stable
RsyslogRsyslogd Version0.9.4_stable
RsyslogRsyslogd Version0.9.5_stable
RsyslogRsyslogd Version0.9.6_stable
RsyslogRsyslogd Version0.9.7_stable
RsyslogRsyslogd Version0.9.8_stable
RsyslogRsyslogd Version1.0.0_stable
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.43% 0.597
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P