HIGH · 7.5

CVE-2010-1923

SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgall...

Vulnerability Description

SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Phpscripte24Web Social Network Freunde Community2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-1923?

CVE-2010-1923 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgall...

How severe is CVE-2010-1923?

CVE-2010-1923 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-1923?

Check the references section above for vendor advisories and patch information. Affected products include: Phpscripte24 Web Social Network Freunde Community.