SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-3197

SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the addrlink parameter to shared/inc/forms/domain_info.php.

MEDIUM 6.5EPSS 1.18%

Does this matter?

Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.

Description

SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the addrlink parameter to shared/inc/forms/domain_info.php. NOTE: CVE-2011-3197 has been SPLIT due to findings by different researchers. CVE-2011-5272 has been assigned for the vps_note parameter to dtcadmin/logPushlet.php vector.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.18% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
gplhost/domain technologie control
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.