VulnerabilityModified
CVE-2008-0363
Multiple SQL injection vulnerabilities in Clever Copy 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to postcomment.php and the (2) album parameter to gallery.php.
HIGH 7.5EPSS 1.10%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Clever Copy 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to postcomment.php and the (2) album parameter to gallery.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- clever copy/clever copy
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/28560
- http://securityreason.com/securityalert/3553
- http://www.securityfocus.com/archive/1/486492/100/0/threaded
- http://www.securityfocus.com/bid/27335
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39746
- http://secunia.com/advisories/28560
- http://securityreason.com/securityalert/3553
- http://www.securityfocus.com/archive/1/486492/100/0/threaded
- http://www.securityfocus.com/bid/27335
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39746
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.