Lucene search

K
cve[email protected]CVE-2012-0805
HistoryJun 05, 2012 - 10:55 p.m.

CVE-2012-0805

2012-06-0522:55:08
CWE-89
web.nvd.nist.gov
187
sql injection
sqlalchemy
keystone
cve-2012-0805
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.3 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.0%

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.

Affected configurations

NVD
Node
sqlalchemysqlalchemyRange0.7.0b3
OR
sqlalchemysqlalchemyMatch0.6.0
OR
sqlalchemysqlalchemyMatch0.6.0beta1
OR
sqlalchemysqlalchemyMatch0.6.0beta2
OR
sqlalchemysqlalchemyMatch0.6.0beta3
OR
sqlalchemysqlalchemyMatch0.6.1
OR
sqlalchemysqlalchemyMatch0.6.2
OR
sqlalchemysqlalchemyMatch0.6.3
OR
sqlalchemysqlalchemyMatch0.6.4
OR
sqlalchemysqlalchemyMatch0.6.5
OR
sqlalchemysqlalchemyMatch0.6.6
OR
sqlalchemysqlalchemyMatch0.6.7
OR
sqlalchemysqlalchemyMatch0.7.0b1
OR
sqlalchemysqlalchemyMatch0.7.0b2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.3 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.0%