VulnerabilityModified
CVE-2009-3975
SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL commands via the gallery_id parameter in a gallery_view action.
MEDIUM 6.8EPSS 0.95%
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL commands via the gallery_id parameter in a gallery_view action.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- moagallery/moa
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/36449Vendor Advisory
- http://www.exploit-db.com/exploits/9481
- http://www.vupen.com/english/advisories/2009/2399Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52707
- http://secunia.com/advisories/36449Vendor Advisory
- http://www.exploit-db.com/exploits/9481
- http://www.vupen.com/english/advisories/2009/2399Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52707
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.