CVE-2010-0631
Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow remote attackers to execute arbitrary SQL commands via the (1) users (username) and (2) passwords parameters.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow remote attackers to execute arbitrary SQL commands via the (1) users (username) and (2) passwords parameters.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- eicrasoft/eicra car rental-script
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/38389Vendor Advisory
- http://www.exploit-db.com/exploits/11323Exploit
- http://secunia.com/advisories/38389Vendor Advisory
- http://www.exploit-db.com/exploits/11323Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.