[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-7242Date: (C)2014-01-03   (M)2024-02-22


SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands via the tableprefix parameter.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.5
Exploit Score: 8.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://seclists.org/bugtraq/2013/Oct/20
BID-62815
http://openwall.com/lists/oss-security/2013/12/29/1
http://openwall.com/lists/oss-security/2013/12/30/10
http://www.enkomio.com/Advisory/SOJOBO-ADV-13-01
http://www.zenphoto.org/news/zenphoto-1.4.5.4

CWE    1
CWE-89

© SecPod Technologies