Vulnerability CVE-2012-5244


Published: 2014-10-20

Description:
Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to functions/widgets.php, (6) the category parameter to functions/print.php; or (7) the name parameter to functions/ajax.php.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Bananadance -> Banana dance 

 References:
https://www.htbridge.com/advisory/HTB23118
http://xforce.iss.net/xforce/xfdb/80746
http://www.exploit-db.com/exploits/23573/
http://osvdb.org/88538
http://osvdb.org/88537
http://osvdb.org/88536
http://osvdb.org/88535

Copyright 2024, cxsecurity.com

 

Back to Top