Lucene search

K
cveMitreCVE-2002-0555
HistoryJul 03, 2002 - 4:00 a.m.

CVE-2002-0555

2002-07-0304:00:00
mitre
web.nvd.nist.gov
28
cve-2002-0555
ibm
informix
web datablade
remote code execution
sql injection
security vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.008

Percentile

81.6%

IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.

Affected configurations

Nvd
Node
ibminformix_web_databladeMatch4.10
OR
ibminformix_web_databladeMatch4.11
OR
ibminformix_web_databladeMatch4.12
OR
ibminformix_web_databladeMatch4.13
VendorProductVersionCPE
ibminformix_web_datablade4.10cpe:2.3:a:ibm:informix_web_datablade:4.10:*:*:*:*:*:*:*
ibminformix_web_datablade4.11cpe:2.3:a:ibm:informix_web_datablade:4.11:*:*:*:*:*:*:*
ibminformix_web_datablade4.12cpe:2.3:a:ibm:informix_web_datablade:4.12:*:*:*:*:*:*:*
ibminformix_web_datablade4.13cpe:2.3:a:ibm:informix_web_datablade:4.13:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.008

Percentile

81.6%

Related for CVE-2002-0555