VulnerabilityModified
CVE-2009-1655
Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password.
MEDIUM 6.5EPSS 1.75%
Does this matter?
Lower severity and a low EPSS score (1.75%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- easy-scripts/answer and question script
- Source
- cve@mitre.org
References
- http://osvdb.org/54502
- http://secunia.com/advisories/35067Vendor Advisory
- http://www.securityfocus.com/bid/34975Exploit
- https://www.exploit-db.com/exploits/8690
- http://osvdb.org/54502
- http://secunia.com/advisories/35067Vendor Advisory
- http://www.securityfocus.com/bid/34975Exploit
- https://www.exploit-db.com/exploits/8690
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.