VulnerabilityModified
CVE-2009-2605
Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser and (2) truppassword cookies to uploadcp/index.php.
MEDIUM 6.8EPSS 1.98%
Does this matter?
Lower severity and a low EPSS score (1.98%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser and (2) truppassword cookies to uploadcp/index.php.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.98% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- traidnt/traidnt up
- Source
- cve@mitre.org
References
- http://osvdb.org/54809
- http://secunia.com/advisories/35273Vendor Advisory
- http://www.exploit-db.com/exploits/8831
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50866
- http://osvdb.org/54809
- http://secunia.com/advisories/35273Vendor Advisory
- http://www.exploit-db.com/exploits/8831
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50866
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.