Vulnerability Description
SQL injection vulnerability in the login feature in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the password parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Preproject | Pre Podcast Portal | All versions |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/40705Vendor Advisory
- http://securityreason.com/securityalert/8469
- http://www.exploit-db.com/exploits/14378Exploit
- http://www.osvdb.org/66511
- http://www.packetstormsecurity.com/1007-exploits/prepodcastportal-sql.txtExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60631
- http://secunia.com/advisories/40705Vendor Advisory
- http://securityreason.com/securityalert/8469
- http://www.exploit-db.com/exploits/14378Exploit
- http://www.osvdb.org/66511
- http://www.packetstormsecurity.com/1007-exploits/prepodcastportal-sql.txtExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60631
FAQ
What is CVE-2010-4959?
CVE-2010-4959 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in the login feature in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the password parameter.
How severe is CVE-2010-4959?
CVE-2010-4959 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-4959?
Check the references section above for vendor advisories and patch information. Affected products include: Preproject Pre Podcast Portal.