CVE-2009-2439
Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party; it is not associated with alibaba.com or the Alibaba Group.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- web development house/alibaba clone
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/0907-exploits/alibabaclone-sql.txtExploit
- http://secunia.com/advisories/35741Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1838Vendor Advisory
- http://packetstormsecurity.org/0907-exploits/alibabaclone-sql.txtExploit
- http://secunia.com/advisories/35741Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1838Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.