HIGH
SQL injection vulnerability in include.php in phpBugTracker 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter
Published Jun 1, 2009
7.5
HIGHCVSS 2.0
EPSS 1.00%
Description
SQL injection vulnerability in include.php in phpBugTracker 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected products
No data.
OR
- ≤ 1.0.4
- 0.1.0
- 0.1.1
- 0.1.2
- 0.1.3
- 0.1.4
- 0.1.5
- 0.1.6
- 0.1.7
- 0.2.0
- 0.2.1
- 0.3.0
- 0.3.1
- 0.3.2
- 0.3.3
- 0.4.0
- 0.5.0
- 0.5.1
- 0.6.0
- 0.6.1
- 0.6.2
- 0.7.0
- 0.7.1
- 0.7.2
- 0.8.0
- 0.8.1
- 0.8.2
- 0.9.0
- 0.9.1
- 1.0
- 1.0.1
- 1.0.3
- 1.x
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- http://www.securityfocus.com/bid/35125 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/1432 vdb-entryx_refsource_VUPENVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/35125 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2009/1432 | vdb-entryx_refsource_VUPENVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 1, 2009
Updated Sep 17, 2024
Reserved Jun 1, 2009
Link CVE-2009-1851
CISA Vulnrichment
Updated n/a