Description
SQL injection vulnerability in Skip 1.0.2 and earlier, and 1.1RC2 and earlier 1.1RC versions, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/34898
Various Sources x_refsource_confirm
http://portal.openskip.org/top/releasenote-ver1-0-0
Third Party Advisory third-party-advisory
x_refsource_jvndb
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000026.html
Issue Tracking x_refsource_confirm
http://dev.openskip.org/redmine/issues/show/677
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35041
Patch third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN03114223/index.html
Scores
EPSS
0.0126
EPSS Percentile
66.5%
Details
CWE
CWE-89
Status
published
Products (5)
openskip/skip
0.9
openskip/skip
1.0.0
openskip/skip
1.0.1
openskip/skip
< 1.0.2
openskip/skip
< 1.1 (2 CPE variants)
Published
Jun 04, 2009
Tracked Since
Feb 18, 2026