Lucene search

K
cve[email protected]CVE-2010-2691
HistoryJul 12, 2010 - 1:27 p.m.

CVE-2010-2691

2010-07-1213:27:28
CWE-89
web.nvd.nist.gov
21
cve-2010-2691
sql injection
2daybiz custom t-shirt design script
remote code execution
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.003

Percentile

70.0%

Multiple SQL injection vulnerabilities in 2daybiz Custom T-Shirt Design Script allow remote attackers to execute arbitrary SQL commands via the (1) sbid parameter to products_details.php, (2) pid parameter to products/products.php, and (3) designid parameter to designview.php.

Affected configurations

NVD
Node
2daybizcustom_t-shirt_design_script
VendorProductVersionCPE
2daybizcustom_t-shirt_design_scriptcpe:/a:2daybiz:custom_t-shirt_design_script::::

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.003

Percentile

70.0%

Related for CVE-2010-2691