CVE-2010-4834
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types…
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the search_management_manage subcontroller. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- oneorzero/aims
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/files/view/95814/oneorzeroaims-lfisql.txtExploit
- http://secunia.com/advisories/42251Vendor Advisory
- http://securityreason.com/securityalert/8375
- http://www.exploit-db.com/exploits/15519Exploit
- http://www.xenuser.org/documents/security/OneOrZero_Aims_multiple_vulnerabilities.txtExploit
- http://packetstormsecurity.org/files/view/95814/oneorzeroaims-lfisql.txtExploit
- http://secunia.com/advisories/42251Vendor Advisory
- http://securityreason.com/securityalert/8375
- http://www.exploit-db.com/exploits/15519Exploit
- http://www.xenuser.org/documents/security/OneOrZero_Aims_multiple_vulnerabilities.txtExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.