Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-6986

SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafted use of FILTER%20regex in a /individual?uri= request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 77.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-6986
  • Duraspace » Vitro » Version: 1.10.0
    cpe:2.3:a:duraspace:vitro:1.10.0


Contact Us

Shodan ® - All rights reserved