Lucene search

K
cveRedhatCVE-2011-4341
HistoryFeb 12, 2012 - 10:55 p.m.

CVE-2011-4341

2012-02-1222:55:01
CWE-79
redhat
web.nvd.nist.gov
28
cve-2011-4341
sql injection
symphony cms
remote authenticated users
arbitrary sql commands

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.1

Confidence

High

EPSS

0.006

Percentile

78.0%

Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author permissions to execute arbitrary SQL commands via the filter parameter to (1) symphony/publish/comments or (2) symphony/publish/images. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks via error messages. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
symphony-cmssymphony_cmsMatch2.2.3
VendorProductVersionCPE
symphony-cmssymphony_cms2.2.3cpe:2.3:a:symphony-cms:symphony_cms:2.2.3:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.1

Confidence

High

EPSS

0.006

Percentile

78.0%

Related for CVE-2011-4341