CVE-2009-1245
Published Apr 6, 2009
Last updated 7 years ago
Overview
- Description
- Multiple SQL injection vulnerabilities in the insert_to_pastebin function in php/cccp-admin/inc/functions.php in CCCP Community Clan Portal Pastebin before 2.80 allow remote attackers to execute arbitrary SQL commands via the (1) subject, (2) language, and (3) nickname parameters to php/cccp-pages/submit.php. NOTE: some of these details are obtained from third party information.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cccp-common-clan-portal-pasterbin:cccp_pastebin:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B14BA363-5A2D-4350-8550-48B79F390800", "versionEndIncluding": "2.70" }, { "criteria": "cpe:2.3:a:cccp-common-clan-portal-pasterbin:cccp_pastebin:2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBB45A98-380D-4916-B7FB-81AAC9E2A0D9" }, { "criteria": "cpe:2.3:a:cccp-common-clan-portal-pasterbin:cccp_pastebin:2.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "201AAECE-F0E4-4F92-9780-51DA068DD17E" }, { "criteria": "cpe:2.3:a:cccp-common-clan-portal-pasterbin:cccp_pastebin:2.30:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4EBF323A-2894-4C04-BE22-8BDE5F19985C" }, { "criteria": "cpe:2.3:a:cccp-common-clan-portal-pasterbin:cccp_pastebin:2.40:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "259ECBB6-9BE1-48AE-8E0E-155895847AAC" }, { "criteria": "cpe:2.3:a:cccp-common-clan-portal-pasterbin:cccp_pastebin:2.50:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB10992C-1E5B-4F17-BD5F-76975B39527B" }, { "criteria": "cpe:2.3:a:cccp-common-clan-portal-pasterbin:cccp_pastebin:2.60:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1440B07C-AB93-4F4A-BA21-58D64F5E7ECD" } ], "operator": "OR" } ] } ]