CVE-2011-5039
Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to login.php, (3) the filter parameter to widget.dokumenti_lista.php, and (4)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to login.php, (3) the filter parameter to widget.dokumenti_lista.php, and (4) the fin_nalog_id parameter to nalozi_naslov.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.01% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- infoproject/biznis heroj
- Source
- cve@mitre.org
References
- http://www.exploit-db.com/exploits/18259Exploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-5064.phpExploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-5065.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71927
- http://www.exploit-db.com/exploits/18259Exploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-5064.phpExploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-5065.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71927
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.