VulnerabilityModified
CVE-2013-7175
Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.
MEDIUM 6.5EPSS 1.29%
Does this matter?
Lower severity and a low EPSS score (1.29%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- avanset/visual certexam manager
- Source
- cret@cert.org
References
- http://osvdb.org/102414
- http://www.kb.cert.org/vuls/id/869702Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/65104
- http://osvdb.org/102414
- http://www.kb.cert.org/vuls/id/869702Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/65104
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.