VulnerabilityModified
CVE-2015-10044
A vulnerability classified as critical was found in gophergala sqldump.
CRITICAL 9.8EPSS 0.64%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability classified as critical was found in gophergala sqldump. This vulnerability affects unknown code. The manipulation leads to sql injection. The patch is identified as 76db54e9073b5248b8863e71a63d66a32d567d21. It is recommended to apply a patch to fix this issue. VDB-218350 is the identifier assigned to this vulnerability.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- sqldump project/sqldump
- Source
- cna@vuldb.com
References
- https://github.com/gophergala/sqldump/commit/76db54e9073b5248b8863e71a63d66a32d567d21Patch, Third Party Advisory
- https://vuldb.com/?ctiid.218350Third Party Advisory
- https://vuldb.com/?id.218350Third Party Advisory
- https://github.com/gophergala/sqldump/commit/76db54e9073b5248b8863e71a63d66a32d567d21Patch, Third Party Advisory
- https://vuldb.com/?ctiid.218350Third Party Advisory
- https://vuldb.com/?id.218350Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.