CVE-2009-2345

Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL commands via unknown parameters to the gbook module and unspecified other components.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
VendorProductVersion
clansphereclansphere
𝑥
≤ 2009.0
clansphereclansphere
2007.4
clansphereclansphere
2007.4.1
clansphereclansphere
2007.4.2
clansphereclansphere
2007.4.3
clansphereclansphere
2007.4.4
clansphereclansphere
2008.1
clansphereclansphere
2008.2
clansphereclansphere
2008.2.1
clansphereclansphere
2009.0:rc1
clansphereclansphere
2009.0:rc2
clansphereclansphere
2009.0:rc3
𝑥
= Vulnerable software versions