VulnerabilityModified
CVE-2015-1434
Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php.
MEDIUM 6.5EPSS 1.85%
Does this matter?
Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- mylittleforum/my little forum
- Source
- cve@mitre.org
References
- http://mylittleforum.net/forum/index.php?id=8182Vendor Advisory
- http://packetstormsecurity.com/files/130356/My-Little-Forum-2.3.3-Cross-Site-Scripting-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/534681/100/0/threadedExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/72575Exploit, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100855Third Party Advisory, VDB Entry
- https://www.htbridge.com/advisory/HTB23248Exploit
- http://mylittleforum.net/forum/index.php?id=8182Vendor Advisory
- http://packetstormsecurity.com/files/130356/My-Little-Forum-2.3.3-Cross-Site-Scripting-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/534681/100/0/threadedExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/72575Exploit, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100855Third Party Advisory, VDB Entry
- https://www.htbridge.com/advisory/HTB23248Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.