CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
76.2%
SQL injection vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to execute SQL commands and read table information via the id parameter.
Vendor | Product | Version | CPE |
---|---|---|---|
slashcode.com | slash | * | cpe:2.3:a:slashcode.com:slash:*:*:*:*:*:*:*:* |
bugs.debian.org/cgi-bin/bugreport.cgi?bug=484499
marc.info/?l=oss-security&m=121258731028005&w=2
marc.info/?l=oss-security&m=121260265427728&w=2
secunia.com/advisories/30551
secunia.com/advisories/31691
securityreason.com/securityalert/3923
slashcode.cvs.sourceforge.net/slashcode/slash/Slash/Utility/Environment/Environment.pm?r1=1.223&r2=1.225
www.debian.org/security/2008/dsa-1633
www.securityfocus.com/bid/29548
www.securitytracker.com/id?1020206
www.slashcode.com/article.pl?sid=08/01/04/1950244&tid=4
www.slashcode.com/article.pl?sid=08/01/07/2314232
exchange.xforce.ibmcloud.com/vulnerabilities/42880