CVE-2010-2672
eZ Publish 3.7.0-4.2.0 - SQL Injection via Search Parameters
Title source: llmDescription
Multiple SQL injection vulnerabilities in eZ Publish 3.7.0 through 4.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) SectionID and (2) SearchTimestamp parameters to the search feature and the (3) SearchContentClassAttributeID parameter to the advancedsearch feature.
References (8)
Core 8
Core References
Various Sources x_refsource_misc
http://www.siberas.de/advisories/advisories_2010.html
Patch x_refsource_confirm
http://ez.no/de/content/download/321165/3192248/version/1/file/16397.diff
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/63237
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/39101
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/38985
Patch x_refsource_confirm
http://ez.no/de/content/download/321166/3192253/version/1/file/16398.diff
Patch, Vendor Advisory x_refsource_confirm
http://ez.no/de/developer/security/security_advisories/ez_publish_4_2/ezsa_2010_001_remote_vulnerability_in_ez_search
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/63238
Scores
EPSS
0.0133
EPSS Percentile
68.1%
Details
CWE
CWE-89
Status
published
Products (14)
ez/ez_publish
3.7.0
ez/ez_publish
3.7.1
ez/ez_publish
3.7.2
ez/ez_publish
3.7.3
ez/ez_publish
3.7.4
ez/ez_publish
3.7.5
ez/ez_publish
3.7.6
ez/ez_publish
3.7.7
ez/ez_publish
3.7.8
ez/ez_publish
3.7.9
... and 4 more
Published
Jul 08, 2010
Tracked Since
Feb 18, 2026