CVE-2017-11174
CRITICALXOOPS 2.5.8.1 - SQL Injection via Database Settings Page
Title source: llmDescription
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://tsublogs.wordpress.com/2017/07/12/xoops-core-2-5-8-1-install-db-sql-injection/
Scores
CVSS v3
9.8
EPSS
0.0103
EPSS Percentile
60.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
xoops/xoops
2.5.8.1
Published
Jul 12, 2017
Tracked Since
Feb 18, 2026