7.5

CVE-2005-3074

SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rsyslog ≫ Rsyslogd Version <= 1.0.1_stable
Rsyslog ≫ Rsyslogd Version <= 1.10.1_development
Rsyslog ≫ Rsyslogd Version 0.8.0_stable
Rsyslog ≫ Rsyslogd Version 0.8.1_stable
Rsyslog ≫ Rsyslogd Version 0.8.2_stable
Rsyslog ≫ Rsyslogd Version 0.8.3_stable
Rsyslog ≫ Rsyslogd Version 0.8.4_stable
Rsyslog ≫ Rsyslogd Version 0.9.0_stable
Rsyslog ≫ Rsyslogd Version 0.9.1_stable
Rsyslog ≫ Rsyslogd Version 0.9.2_stable
Rsyslog ≫ Rsyslogd Version 0.9.3_stable
Rsyslog ≫ Rsyslogd Version 0.9.4_stable
Rsyslog ≫ Rsyslogd Version 0.9.5_stable
Rsyslog ≫ Rsyslogd Version 0.9.6_stable
Rsyslog ≫ Rsyslogd Version 0.9.7_stable
Rsyslog ≫ Rsyslogd Version 0.9.8_stable
Rsyslog ≫ Rsyslogd Version 1.0.0_stable
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.11% 0.617
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/16947
Patch
http://www.rsyslog.com/Article35.phtml