VulnerabilityModified
CVE-2008-1871
SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to execute arbitrary SQL commands via the cat_id parameter in a list action.
MEDIUM 6.5EPSS 0.92%
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to execute arbitrary SQL commands via the cat_id parameter in a list action.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- scriptsagent/links directory
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29710Vendor Advisory
- http://www.securityfocus.com/bid/28655
- http://www.vupen.com/english/advisories/2008/1126/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41661
- https://www.exploit-db.com/exploits/5377
- http://secunia.com/advisories/29710Vendor Advisory
- http://www.securityfocus.com/bid/28655
- http://www.vupen.com/english/advisories/2008/1126/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41661
- https://www.exploit-db.com/exploits/5377
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.