7.5
CVE-2005-4408
- EPSS 1.24%
- Veröffentlicht 20.12.2005 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:18:44
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in Miraserver 1.0 RC4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) id parameter to newsitem.php, and (3) cat parameter to article.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pc Media ≫ Miraserver Version <= 1.0_rc4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.24% | 0.654 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://pridels0.blogspot.com/2005/12/miraserver-sql-vuln.html
http://secunia.com/advisories/18110
http://www.osvdb.org/21836
http://www.osvdb.org/21837
http://www.osvdb.org/21838
http://www.securityfocus.com/bid/15960