Lucene search

K
cveMitreCVE-2011-5071
HistoryJan 29, 2012 - 4:04 a.m.

CVE-2011-5071

2012-01-2904:04:44
CWE-89
mitre
web.nvd.nist.gov
23
cve-2011-5071
sql injection
support incident tracker
sit!
remote attackers
nvd
security vulnerabilities

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.7

Confidence

Low

EPSS

0.001

Percentile

48.1%

Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php, (2) selected[] parameter to tasks.php, (3) sites[] parameter to billable_incidents.php, or (4) search_string parameter to search.php. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
sitrackersupport_incident_trackerRange3.63
OR
sitrackersupport_incident_trackerMatch3.6
OR
sitrackersupport_incident_trackerMatch3.21
OR
sitrackersupport_incident_trackerMatch3.22
OR
sitrackersupport_incident_trackerMatch3.22pl1
OR
sitrackersupport_incident_trackerMatch3.23
OR
sitrackersupport_incident_trackerMatch3.24
OR
sitrackersupport_incident_trackerMatch3.24beta-2
OR
sitrackersupport_incident_trackerMatch3.30
OR
sitrackersupport_incident_trackerMatch3.30beta2
OR
sitrackersupport_incident_trackerMatch3.31
OR
sitrackersupport_incident_trackerMatch3.32
OR
sitrackersupport_incident_trackerMatch3.33
OR
sitrackersupport_incident_trackerMatch3.35
OR
sitrackersupport_incident_trackerMatch3.35beta1
OR
sitrackersupport_incident_trackerMatch3.36
OR
sitrackersupport_incident_trackerMatch3.40
OR
sitrackersupport_incident_trackerMatch3.40beta1
OR
sitrackersupport_incident_trackerMatch3.41
OR
sitrackersupport_incident_trackerMatch3.45
OR
sitrackersupport_incident_trackerMatch3.45beta1
OR
sitrackersupport_incident_trackerMatch3.50
OR
sitrackersupport_incident_trackerMatch3.50beta1
OR
sitrackersupport_incident_trackerMatch3.51
OR
sitrackersupport_incident_trackerMatch3.60
OR
sitrackersupport_incident_trackerMatch3.61
OR
sitrackersupport_incident_trackerMatch3.62
OR
sitrackersupport_incident_trackerMatch3.63beta1
VendorProductVersionCPE
sitrackersupport_incident_tracker*cpe:2.3:a:sitracker:support_incident_tracker:*:*:*:*:*:*:*:*
sitrackersupport_incident_tracker3.6cpe:2.3:a:sitracker:support_incident_tracker:3.6:*:*:*:*:*:*:*
sitrackersupport_incident_tracker3.21cpe:2.3:a:sitracker:support_incident_tracker:3.21:*:*:*:*:*:*:*
sitrackersupport_incident_tracker3.22cpe:2.3:a:sitracker:support_incident_tracker:3.22:*:*:*:*:*:*:*
sitrackersupport_incident_tracker3.22pl1cpe:2.3:a:sitracker:support_incident_tracker:3.22pl1:*:*:*:*:*:*:*
sitrackersupport_incident_tracker3.23cpe:2.3:a:sitracker:support_incident_tracker:3.23:*:*:*:*:*:*:*
sitrackersupport_incident_tracker3.24cpe:2.3:a:sitracker:support_incident_tracker:3.24:*:*:*:*:*:*:*
sitrackersupport_incident_tracker3.24cpe:2.3:a:sitracker:support_incident_tracker:3.24:beta-2:*:*:*:*:*:*
sitrackersupport_incident_tracker3.30cpe:2.3:a:sitracker:support_incident_tracker:3.30:*:*:*:*:*:*:*
sitrackersupport_incident_tracker3.30cpe:2.3:a:sitracker:support_incident_tracker:3.30:beta2:*:*:*:*:*:*
Rows per page:
1-10 of 281

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.7

Confidence

Low

EPSS

0.001

Percentile

48.1%

Related for CVE-2011-5071