CVE-2013-2559
Published Mar 27, 2014
Last updated 4 years ago
Overview
- Description
- SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.5
- Impact score
- 6.4
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:getsymphony:symphony:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6C440112-0B21-4832-A89C-1A343B627039", "versionEndIncluding": "2.3.1" }, { "criteria": "cpe:2.3:a:getsymphony:symphony:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "254956B4-E86A-429C-A8E6-0ABA833A9DB6" }, { "criteria": "cpe:2.3:a:getsymphony:symphony:2.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13379528-0C53-474F-B2E7-D5650C7F5F3C" }, { "criteria": "cpe:2.3:a:getsymphony:symphony:2.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8865CA96-3DF6-4499-8CEC-59977CC86FEB" }, { "criteria": "cpe:2.3:a:getsymphony:symphony:2.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "570A8AE5-E4A6-4400-982C-F725D15E35ED" }, { "criteria": "cpe:2.3:a:getsymphony:symphony:2.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB2D9ACA-2A2A-4169-A8AC-ED259921E24B" }, { "criteria": "cpe:2.3:a:getsymphony:symphony:2.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "394B8CA2-4C11-4C2C-8BFE-C2BADA341502" }, { "criteria": "cpe:2.3:a:getsymphony:symphony:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C9D49697-497A-44EC-892B-DB8C5545AFE4" }, { "criteria": "cpe:2.3:a:getsymphony:symphony:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C922F66F-8E3D-404C-95B7-C57DA8DDC162" }, { "criteria": "cpe:2.3:a:getsymphony:symphony:2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF41854C-206A-4BCF-B6FD-55253E3BC0AF" } ], "operator": "OR" } ] } ]