6.8
CVE-2007-4437
- EPSS 1.28%
- Veröffentlicht 20.08.2007 22:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:05
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match parameter. NOTE: some details are obtained from third party information.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.28% | 0.662 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://bugs.gentoo.org/show_bug.cgi?id=189607
http://osvdb.org/38276
http://secunia.com/advisories/26542
http://secunia.com/advisories/27253
http://security.gentoo.org/glsa/glsa-200710-13.xml
http://www.ampache.org/announce/3_3_3_5.php
http://www.securityfocus.com/bid/25362
https://exchange.xforce.ibmcloud.com/vulnerabilities/36121