CVE-2009-4698
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- alexandre amaral/xoops celepar
- Source
- cve@mitre.org
References
- http://osvdb.org/56593
- http://osvdb.org/56595
- http://secunia.com/advisories/35966Vendor Advisory
- http://www.exploit-db.com/exploits/9249
- http://www.exploit-db.com/exploits/9261
- http://www.osvdb.org/56594
- http://www.securityfocus.com/bid/35820Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51985
- http://osvdb.org/56593
- http://osvdb.org/56595
- http://secunia.com/advisories/35966Vendor Advisory
- http://www.exploit-db.com/exploits/9249
- http://www.exploit-db.com/exploits/9261
- http://www.osvdb.org/56594
- http://www.securityfocus.com/bid/35820Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51985
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.