CVE-2008-3887
Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects action, and (2) remote authenticated administrators to execute arbitrary…
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects action, and (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in a viewuser action.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- dotproject/dotproject
- Source
- cve@mitre.org
References
- http://packetstorm.linuxsecurity.com/0808-exploits/dotproject-sqlxss.txtExploit
- http://secunia.com/advisories/31681Vendor Advisory
- http://www.securityfocus.com/bid/30924
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44771
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44772
- http://packetstorm.linuxsecurity.com/0808-exploits/dotproject-sqlxss.txtExploit
- http://secunia.com/advisories/31681Vendor Advisory
- http://www.securityfocus.com/bid/30924
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44771
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44772
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.