Lucene search

K
cve[email protected]CVE-2007-2898
HistoryMay 30, 2007 - 10:30 a.m.

CVE-2007-2898

2007-05-3010:30:00
CWE-89
web.nvd.nist.gov
28
cve-2007-2898
sql injection
2z project 0.9.5
rating.php
remote attackers
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.4 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.4%

SQL injection vulnerability in includes/rating.php in 2z Project 0.9.5 allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.

Affected configurations

NVD
Node
2z_project2z_projectMatch0.9.5
CPENameOperatorVersion
2z_project:2z_project2z projecteq0.9.5

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.4 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.4%

Related for CVE-2007-2898