CVE-2010-3267

UnknownEPSS 1.94%

Last modified

CVE-2010-3267 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the qu_id parameter to bugs.aspx, (2) the row_id parameter to delete_query.aspx, the (3) new_project or (4) us_id parameter to edit_bug.aspx, or (5) the bug_list parameter to massedit.aspx. NOTE: some of these details are obtained from third party information.. EPSS estimates a 1.94% chance of exploitation in the next 30 days.

Description

Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the qu_id parameter to bugs.aspx, (2) the row_id parameter to delete_query.aspx, the (3) new_project or (4) us_id parameter to edit_bug.aspx, or (5) the bug_list parameter to massedit.aspx. NOTE: some of these details are obtained from third party information.

Metrics

EPSS Probability
1.94%

77.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IfdefinedBugtracker.Net<= 3.4.4
IfdefinedBugtracker.Net0.91
IfdefinedBugtracker.Net2.4.1
IfdefinedBugtracker.Net2.4.2
IfdefinedBugtracker.Net2.4.3
IfdefinedBugtracker.Net2.4.4
IfdefinedBugtracker.Net2.4.5
IfdefinedBugtracker.Net2.4.6
IfdefinedBugtracker.Net2.4.7
IfdefinedBugtracker.Net2.4.8
IfdefinedBugtracker.Net2.5.0
IfdefinedBugtracker.Net2.5.1
IfdefinedBugtracker.Net2.5.2
IfdefinedBugtracker.Net2.5.3
IfdefinedBugtracker.Net2.5.4
IfdefinedBugtracker.Net2.5.5
IfdefinedBugtracker.Net2.5.6
IfdefinedBugtracker.Net2.5.7
IfdefinedBugtracker.Net2.5.8
IfdefinedBugtracker.Net2.5.9
IfdefinedBugtracker.Net2.6.0
IfdefinedBugtracker.Net2.6.1
IfdefinedBugtracker.Net2.6.2
IfdefinedBugtracker.Net2.6.3
IfdefinedBugtracker.Net2.6.4
IfdefinedBugtracker.Net2.6.5
IfdefinedBugtracker.Net2.6.6
IfdefinedBugtracker.Net2.6.7
IfdefinedBugtracker.Net2.6.8
IfdefinedBugtracker.Net2.6.9
IfdefinedBugtracker.Net2.7.0
IfdefinedBugtracker.Net2.7.1
IfdefinedBugtracker.Net2.7.2
IfdefinedBugtracker.Net2.7.3
IfdefinedBugtracker.Net2.7.4
IfdefinedBugtracker.Net2.7.5
IfdefinedBugtracker.Net2.7.6
IfdefinedBugtracker.Net2.7.7
IfdefinedBugtracker.Net2.7.8
IfdefinedBugtracker.Net2.7.9
IfdefinedBugtracker.Net2.8.0
IfdefinedBugtracker.Net2.8.1
IfdefinedBugtracker.Net2.8.2
IfdefinedBugtracker.Net2.8.3
IfdefinedBugtracker.Net2.8.4
IfdefinedBugtracker.Net2.8.5
IfdefinedBugtracker.Net2.8.6
IfdefinedBugtracker.Net2.8.7
IfdefinedBugtracker.Net2.8.8
IfdefinedBugtracker.Net2.8.9

Showing 50 of 85 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-3267?
Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the qu_id parameter to bugs.aspx, (2) the row_id parameter to delete_query.aspx, the (3) new_project or (4) us_id parameter to edit_bug.aspx, or (5) the bug_list parameter to massedit.aspx. NOTE: some of these details are obtained from third party information.
How severe is CVE-2010-3267?
Severity scoring for CVE-2010-3267 is pending analysis. The EPSS model estimates a 1.94% probability of exploitation in the next 30 days.
How do I fix CVE-2010-3267?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-3267?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST