Description
Multiple SQL injection vulnerabilities in ssearch.php in Siche search module 0.5 for Zeroboard allow remote attackers to execute arbitrary SQL commands via the (1) ss, (2) sm, (3) align, or (4) category parameters.
References (5)
Core 5
Core References
Various Sources x_refsource_misc
http://www.vulnerability-lab.com/get_content.php?id=504
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/53035
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/81178
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74916
Exploit mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-04/0099.html
Scores
EPSS
0.0131
EPSS Percentile
67.7%
Details
CWE
CWE-89
Status
published
Products (1)
eos.pe/siche_search_module
0.5
Published
Aug 31, 2012
Tracked Since
Feb 18, 2026