Description
Multiple SQL injection vulnerabilities in the get_sample_filters_by_signature function in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to execute arbitrary SQL commands via the (1) agent or (2) object id.
References (7)
Core 7
Core References
Issue Tracking x_refsource_misc
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=830245
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092562.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/55618
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1278.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1281.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/50660
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092543.html
Scores
EPSS
0.0213
EPSS Percentile
80.0%
Details
CWE
CWE-89
Status
published
Products (21)
redhat/enterprise_mrg
2.0
trevor_mckay/cumin
0.1.3160-1
trevor_mckay/cumin
0.1.4369-1
trevor_mckay/cumin
0.1.4410-2
trevor_mckay/cumin
0.1.4494-1
trevor_mckay/cumin
0.1.4794-1
trevor_mckay/cumin
0.1.4916-1
trevor_mckay/cumin
0.1.5033-1
trevor_mckay/cumin
0.1.5037-1
trevor_mckay/cumin
0.1.5054-1
... and 11 more
Published
Sep 28, 2012
Tracked Since
Feb 18, 2026