VulnerabilityModified
CVE-2010-1923
SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.
HIGH 7.5EPSS 0.97%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- phpscripte24/web social network freunde community
- Source
- cve@mitre.org
References
- http://osvdb.org/64513
- http://packetstormsecurity.org/1005-exploits/web20snfcs-sql.txtExploit
- http://secunia.com/advisories/39761Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58583
- http://osvdb.org/64513
- http://packetstormsecurity.org/1005-exploits/web20snfcs-sql.txtExploit
- http://secunia.com/advisories/39761Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58583
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.