CVE-2008-6013

Multiple SQL injection vulnerabilities in Freeway before 1.4.3.210 allow remote attackers to execute arbitrary SQL commands via unspecified vectors involving the (1) advanced search result and (2) service resource pages.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
VendorProductVersion
openfreewayfreeway
𝑥
≤ 1.4.2.197
openfreewayfreeway
1.0.25
openfreewayfreeway
1.0.25:public_beta
openfreewayfreeway
1.0.59
openfreewayfreeway
1.0.060
openfreewayfreeway
1.1.1.76
openfreewayfreeway
1.1.1.80
openfreewayfreeway
1.1.1.81
openfreewayfreeway
1.2.0.113
openfreewayfreeway
1.3
openfreewayfreeway
1.3.0.142
openfreewayfreeway
1.3.1.142
openfreewayfreeway
1.3.1.147
openfreewayfreeway
1.3.2.154
openfreewayfreeway
1.3.2.160
openfreewayfreeway
1.3.2.160:joomla_beta
openfreewayfreeway
1.4
openfreewayfreeway
1.4.0.171
openfreewayfreeway
1.4.1
openfreewayfreeway
1.4.1.171
openfreewayfreeway
1.4.1.197
𝑥
= Vulnerable software versions