Lucene search

K
cvelistMitreCVELIST:CVE-2012-0973
HistorySep 25, 2012 - 11:00 p.m.

CVE-2012-0973

2012-09-2523:00:00
mitre
www.cve.org
5
osclass
sql injection
remote attackers
scategory parameter
index.php
osc_search_category_id
findbyslug function

AI Score

8.5

Confidence

Low

EPSS

0.005

Percentile

75.6%

Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands via the sCategory parameter to index.php, which is not properly handled by the (1) osc_search_category_id function in oc-includes/osclass/helpers/hSearch.php and (2) findBySlug function oc-includes/osclass/model/Category.php. NOTE: some of these details are obtained from third party information.

AI Score

8.5

Confidence

Low

EPSS

0.005

Percentile

75.6%

Related for CVELIST:CVE-2012-0973