Lucene search

K
cveMitreCVE-2008-3366
HistoryJul 30, 2008 - 5:41 p.m.

CVE-2008-3366

2008-07-3017:41:00
CWE-89
mitre
web.nvd.nist.gov
49
cve-2008-3366
sql injection
pligg cms
beta 9.9.0
remote attack
arbitrary sql commands

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

Low

EPSS

0.001

Percentile

44.2%

SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-1774.

Affected configurations

Nvd
Node
pliggpligg_cmsMatch9.9.0
OR
pliggpligg_cmsMatch9.9.0beta
VendorProductVersionCPE
pliggpligg_cms9.9.0cpe:2.3:a:pligg:pligg_cms:9.9.0:*:*:*:*:*:*:*
pliggpligg_cms9.9.0cpe:2.3:a:pligg:pligg_cms:9.9.0:beta:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

Low

EPSS

0.001

Percentile

44.2%

Related for CVE-2008-3366