VulnerabilityModified
CVE-2008-2760
SQL injection vulnerability in searchbanners.asp in Xigla Absolute Banner Manager XE 2.0 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
MEDIUM 6.5EPSS 1.16%
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in searchbanners.asp in Xigla Absolute Banner Manager XE 2.0 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- xigla/absolute banner manager
- Source
- cve@mitre.org
References
- http://bugreport.ir/index.php?/41Exploit
- http://marc.info/?l=bugtraq&m=121322052622903&w=2Exploit
- http://secunia.com/advisories/30641Vendor Advisory
- http://securityreason.com/securityalert/3950
- http://www.securityfocus.com/bid/29672
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43046
- http://bugreport.ir/index.php?/41Exploit
- http://marc.info/?l=bugtraq&m=121322052622903&w=2Exploit
- http://secunia.com/advisories/30641Vendor Advisory
- http://securityreason.com/securityalert/3950
- http://www.securityfocus.com/bid/29672
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43046
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.