Lucene search

K
cveMitreCVE-2009-0458
HistoryFeb 10, 2009 - 7:00 a.m.

CVE-2009-0458

2009-02-1007:00:24
CWE-89
mitre
web.nvd.nist.gov
28
cve
sql injection
admin/login_submit.php
whole hog ware support 1.x
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.001

Percentile

42.0%

Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
wholehogsoftwareware_supportMatch1.0
VendorProductVersionCPE
wholehogsoftwareware_support1.0cpe:2.3:a:wholehogsoftware:ware_support:1.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.001

Percentile

42.0%

Related for CVE-2009-0458