CVE-2009-2010
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) thread parameter to messageboard.php, (2) member parameter to…
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) thread parameter to messageboard.php, (2) member parameter to profile.php, (3) pid parameter to gallery/index.php, and the (4) fcms_login_id cookie parameter.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- haudenschilt/family connections cms
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/35039Vendor Advisory
- http://www.securityfocus.com/archive/1/503477/100/0/threaded
- http://www.securityfocus.com/bid/34935Exploit
- http://www.vupen.com/english/advisories/2009/1306Vendor Advisory
- https://www.exploit-db.com/exploits/8671
- http://secunia.com/advisories/35039Vendor Advisory
- http://www.securityfocus.com/archive/1/503477/100/0/threaded
- http://www.securityfocus.com/bid/34935Exploit
- http://www.vupen.com/english/advisories/2009/1306Vendor Advisory
- https://www.exploit-db.com/exploits/8671
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.