VulnerabilityModified
CVE-2009-3970
SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action.
MEDIUM 6.5EPSS 0.89%
Does this matter?
Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- phpdirsubmit/php dir submit
- Source
- cve@mitre.org
References
- http://www.exploit-db.com/exploits/9484
- http://www.vupen.com/english/advisories/2009/2401Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52709
- http://www.exploit-db.com/exploits/9484
- http://www.vupen.com/english/advisories/2009/2401Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52709
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.