VulnerabilityModified
CVE-2008-2757
SQL injection vulnerability in search.asp in Xigla Absolute News Manager XE 3.2 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
MEDIUM 6.5EPSS 1.16%
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in search.asp in Xigla Absolute News Manager XE 3.2 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- xigla/absolute news manager xe
- Source
- cve@mitre.org
References
- http://bugreport.ir/index.php?/41Exploit
- http://marc.info/?l=bugtraq&m=121322052622903&w=2Exploit
- http://secunia.com/advisories/30643Vendor Advisory
- http://securityreason.com/securityalert/3950
- http://www.securityfocus.com/bid/29672
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43043
- http://bugreport.ir/index.php?/41Exploit
- http://marc.info/?l=bugtraq&m=121322052622903&w=2Exploit
- http://secunia.com/advisories/30643Vendor Advisory
- http://securityreason.com/securityalert/3950
- http://www.securityfocus.com/bid/29672
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43043
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.