CVE-2008-5816
Published Jan 2, 2009
Last updated 7 years ago
Overview
- Description
- SQL injection vulnerability in repository.php in ILIAS 3.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ref_id parameter.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CFC5B28-895E-4971-A86F-ED85C699EED2", "versionEndIncluding": "3.7.4" }, { "criteria": "cpe:2.3:a:ilias:ilias:3.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10EED163-BE06-47A2-8CA0-CFC7E49122A7" }, { "criteria": "cpe:2.3:a:ilias:ilias:3.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "547EFE80-4B92-45D0-BCCB-2AC8DD50706D" }, { "criteria": "cpe:2.3:a:ilias:ilias:3.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7FE83C2-8A4C-437D-AF9B-89B4F35CFF6E" }, { "criteria": "cpe:2.3:a:ilias:ilias:3.7.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "423BD17F-D648-424A-A494-C5B158E12F9A" } ], "operator": "OR" } ] } ]