Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-4698

Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 82.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2009-4698
  • Alexandre Amaral » Xoops Celepar » Version: 1.0.1
    cpe:2.3:a:alexandre_amaral:xoops_celepar:1.0.1
  • Xoops » Xoops » Version: 2.5.10
    cpe:2.3:a:xoops:xoops:2.5.10
  • Xoops » Xoops » Version: 2.5.6
    cpe:2.3:a:xoops:xoops:2.5.6
  • Xoops » Xoops » Version: 2.5.7
    cpe:2.3:a:xoops:xoops:2.5.7
  • Xoops » Xoops » Version: 2.5.7.2
    cpe:2.3:a:xoops:xoops:2.5.7.2
  • Xoops » Xoops » Version: 2.5.7.3
    cpe:2.3:a:xoops:xoops:2.5.7.3
  • Xoops » Xoops » Version: 2.5.8
    cpe:2.3:a:xoops:xoops:2.5.8
  • Xoops » Xoops » Version: 2.5.8.1
    cpe:2.3:a:xoops:xoops:2.5.8.1


Contact Us

Shodan ® - All rights reserved