VulnerabilityModified
CVE-2008-1990
Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) cID parameter to default.asp and the (2) username parameter to main_login2.asp.
HIGH 7.5EPSS 1.19%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) cID parameter to default.asp and the (2) username parameter to main_login2.asp.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- acidcat/acidcat cms
- Source
- cve@mitre.org
References
- http://bugreport.ir/index.php?/36Exploit
- http://secunia.com/advisories/29916Vendor Advisory
- http://securityreason.com/securityalert/3842
- http://www.securityfocus.com/archive/1/491129/100/0/threaded
- http://www.securityfocus.com/bid/28868Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41918
- https://www.exploit-db.com/exploits/5478
- http://bugreport.ir/index.php?/36Exploit
- http://secunia.com/advisories/29916Vendor Advisory
- http://securityreason.com/securityalert/3842
- http://www.securityfocus.com/archive/1/491129/100/0/threaded
- http://www.securityfocus.com/bid/28868Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41918
- https://www.exploit-db.com/exploits/5478
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.