7.5

CVE-2011-4066

Exploit
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sir ≫ Gnuboard Version <= 4.33.02
Sir ≫ Gnuboard Version 3.30
Sir ≫ Gnuboard Version 3.31
Sir ≫ Gnuboard Version 3.32
Sir ≫ Gnuboard Version 3.33
Sir ≫ Gnuboard Version 3.34
Sir ≫ Gnuboard Version 3.35
Sir ≫ Gnuboard Version 3.36
Sir ≫ Gnuboard Version 3.37
Sir ≫ Gnuboard Version 3.38
Sir ≫ Gnuboard Version 3.39
Sir ≫ Gnuboard Version 3.40
Sir ≫ Gnuboard Version 4.31.03
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.67% 0.738
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

http://www.exploit-db.com/exploits/17992
Exploit
http://www.securityfocus.com/bid/50173
http://www.securitytracker.com/id?1026197
https://exchange.xforce.ibmcloud.com/vulnerabilities/70686