Vulnerability CVE-2012-4743


Published: 2012-08-31   Modified: 2012-09-01

Description:
Multiple SQL injection vulnerabilities in ssearch.php in Siche search module 0.5 for Zeroboard allow remote attackers to execute arbitrary SQL commands via the (1) ss, (2) sm, (3) align, or (4) category parameters.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Eos.pe -> Siche search module 

 References:
http://xforce.iss.net/xforce/xfdb/74916
http://www.vulnerability-lab.com/get_content.php?id=504
http://www.securityfocus.com/bid/53035
http://osvdb.org/81178
http://archives.neohapsis.com/archives/bugtraq/2012-04/0099.html

Copyright 2024, cxsecurity.com

 

Back to Top