Lucene search

K
cve[email protected]CVE-2009-2345
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-2345

2022-10-0316:24:06
CWE-89
web.nvd.nist.gov
19
clansphere
sql injection
cve-2009-2345
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

49.1%

Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL commands via unknown parameters to the gbook module and unspecified other components.

Affected configurations

NVD
Node
clansphereclansphereRange2009.0
OR
clansphereclansphereMatch2007.4
OR
clansphereclansphereMatch2007.4.1
OR
clansphereclansphereMatch2007.4.2
OR
clansphereclansphereMatch2007.4.3
OR
clansphereclansphereMatch2007.4.4
OR
clansphereclansphereMatch2008
OR
clansphereclansphereMatch2008.1
OR
clansphereclansphereMatch2008.2
OR
clansphereclansphereMatch2008.2.1
OR
clansphereclansphereMatch2009.0rc1
OR
clansphereclansphereMatch2009.0rc2
OR
clansphereclansphereMatch2009.0rc3

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

49.1%

Related for CVE-2009-2345