Lucene search

K
cve[email protected]CVE-2010-3212
HistorySep 03, 2010 - 6:00 p.m.

CVE-2010-3212

2010-09-0318:00:04
CWE-89
web.nvd.nist.gov
28
cve-2010-3212
sql injection
seagull
security vulnerability
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

37.7%

SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO.

Affected configurations

NVD
Node
seagullproject.orgseagullRange0.6.7
OR
seagullproject.orgseagullMatch0.4.6
OR
seagullproject.orgseagullMatch0.4.7
OR
seagullproject.orgseagullMatch0.6.0
OR
seagullproject.orgseagullMatch0.6.0rc1
OR
seagullproject.orgseagullMatch0.6.0rc2
OR
seagullproject.orgseagullMatch0.6.0rc3
OR
seagullproject.orgseagullMatch0.6.1
OR
seagullproject.orgseagullMatch0.6.2
OR
seagullproject.orgseagullMatch0.6.3
OR
seagullproject.orgseagullMatch0.6.4
OR
seagullproject.orgseagullMatch0.6.5
OR
seagullproject.orgseagullMatch0.6.6

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

37.7%

Related for CVE-2010-3212