CVE-2012-2338
Published May 21, 2012
Last updated 12 years ago
Overview
- Description
- SQL injection vulnerability in includes/picture.class.php in Galette 0.63, 0.63.1, 0.63.2, 0.63.3, and 0.64rc1 allows remote attackers to execute arbitrary SQL commands via the id_adh parameter to picture.php.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:johan_cwiklinski:galette:0.63:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "38248649-CD2E-450C-89E6-34A88BAAFAA7" }, { "criteria": "cpe:2.3:a:johan_cwiklinski:galette:0.63:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84E13905-5F75-4F1C-8FD3-E3602EFD91B4" }, { "criteria": "cpe:2.3:a:johan_cwiklinski:galette:0.63.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A00F6E3-A0E9-4AEF-86F0-E06E422513EF" }, { "criteria": "cpe:2.3:a:johan_cwiklinski:galette:0.63.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F398661-E8C1-4D9F-B1FF-8DBB0C22294B" }, { "criteria": "cpe:2.3:a:johan_cwiklinski:galette:0.63.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3679734A-F656-4CFA-A4FE-DEE01F4895DA" } ], "operator": "OR" } ] } ]