Vulnerability Description
Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the qu_id parameter to bugs.aspx, (2) the row_id parameter to delete_query.aspx, the (3) new_project or (4) us_id parameter to edit_bug.aspx, or (5) the bug_list parameter to massedit.aspx. NOTE: some of these details are obtained from third party information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ifdefined | Bugtracker.Net | <= 3.4.4 |
Related Weaknesses (CWE)
References
- http://btnet.svn.sourceforge.net/viewvc/btnet/RELEASE_NOTES.TXT?revision=578&vie
- http://secunia.com/advisories/42418Vendor Advisory
- http://www.coresecurity.com/content/multiple-vulnerabilities-in-bugtracker
- http://www.exploit-db.com/exploits/15653Exploit
- http://www.securityfocus.com/archive/1/514957/100/0/threaded
- http://www.securityfocus.com/bid/45121
- http://btnet.svn.sourceforge.net/viewvc/btnet/RELEASE_NOTES.TXT?revision=578&vie
- http://secunia.com/advisories/42418Vendor Advisory
- http://www.coresecurity.com/content/multiple-vulnerabilities-in-bugtracker
- http://www.exploit-db.com/exploits/15653Exploit
- http://www.securityfocus.com/archive/1/514957/100/0/threaded
- http://www.securityfocus.com/bid/45121
FAQ
What is CVE-2010-3267?
CVE-2010-3267 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the qu_id parameter to bugs.aspx, (2) the row_id parame...
How severe is CVE-2010-3267?
CVE-2010-3267 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-3267?
Check the references section above for vendor advisories and patch information. Affected products include: Ifdefined Bugtracker.Net.