CVE-2005-4478
Published Dec 22, 2005
Last updated 13 years ago
Overview
- Description
- Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:papoo:papoo:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "971FF217-A1E4-4564-9AF0-302D273C78F1", "versionEndIncluding": "2.1.2" } ], "operator": "OR" } ] } ]