VulnerabilityModified
CVE-2008-4303
Multiple SQL injection vulnerabilities in phpCollab 2.5 rc3, 2.4, and earlier allow remote attackers to execute arbitrary SQL commands via the loginForm parameter to general/login.php, and unspecified other vectors.
MEDIUM 6.8EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in phpCollab 2.5 rc3, 2.4, and earlier allow remote attackers to execute arbitrary SQL commands via the loginForm parameter to general/login.php, and unspecified other vectors.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- php-collab/php-collab
- Source
- secalert@redhat.com
References
- http://bugs.gentoo.org/show_bug.cgi?id=235052
- http://secunia.com/advisories/19449Vendor Advisory
- http://secunia.com/advisories/33258Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200812-20.xml
- http://www.securityfocus.com/bid/32964
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47520
- http://bugs.gentoo.org/show_bug.cgi?id=235052
- http://secunia.com/advisories/19449Vendor Advisory
- http://secunia.com/advisories/33258Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200812-20.xml
- http://www.securityfocus.com/bid/32964
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47520
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.