CVE-2010-2673
Published Jul 8, 2010
Last updated 14 years ago
Overview
- Description
- SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:devana:devana:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0DA264A7-EDD4-4BE9-86D5-019DCF2A4A96", "versionEndIncluding": "1.6.6" }, { "criteria": "cpe:2.3:a:devana:devana:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "589A985F-DE76-4EF0-8C86-E3FA20D5C719" }, { "criteria": "cpe:2.3:a:devana:devana:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1FFC7192-A0E9-4C9B-8476-3F762FAEB7AF" }, { "criteria": "cpe:2.3:a:devana:devana:1.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "761FF8EF-F70E-4526-A018-6215E36A5687" }, { "criteria": "cpe:2.3:a:devana:devana:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CB6D45C-462E-4D9B-99EA-B4B6B17EBA9A" }, { "criteria": "cpe:2.3:a:devana:devana:1.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4FB61534-A979-4A60-8D41-22B78F99620E" }, { "criteria": "cpe:2.3:a:devana:devana:1.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9F6CC6C5-0D7F-40AF-BC5B-2D75FE734619" } ], "operator": "OR" } ] } ]