HIGH · 7.5

CVE-2010-3076

The filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection ...

Vulnerability Description

The filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via the username parameter to the admin login page.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
BlentzSmbind<= 0.4.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-3076?

CVE-2010-3076 is a vulnerability with a CVSS score of 7.5 (HIGH). The filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection ...

How severe is CVE-2010-3076?

CVE-2010-3076 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-3076?

Check the references section above for vendor advisories and patch information. Affected products include: Blentz Smbind.