VulnerabilityModified
CVE-2005-0368
Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.
HIGH 7.5EPSS 2.33%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.33% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- chipmunk scripts/cmscore
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=110803385223054&w=2
- http://secunia.com/advisories/14142/Vendor Advisory
- http://www.securityfocus.com/bid/12457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19235
- http://marc.info/?l=bugtraq&m=110803385223054&w=2
- http://secunia.com/advisories/14142/Vendor Advisory
- http://www.securityfocus.com/bid/12457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19235
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.