Vulnerability Details CVE-2010-4152
SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the i and th vectors are already covered by CVE-2009-0646.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.7%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2010-4152
-
cpe:2.3:a:4site:4site_cms:*
-
cpe:2.3:a:4site:4site_cms:2.0
-
cpe:2.3:a:4site:4site_cms:2.2