CVE-2010-1865

Multiple SQL injection vulnerabilities in ClanSphere 2009.0.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the IP address to the cs_getip function in generate.php in the Captcha module, or (2) the s_email parameter to the cs_sql_select function in the MySQL database driver (mysql.php).
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
csphereclansphere
𝑥
≤ 2009.0.3
csphereclansphere
2007.0
csphereclansphere
2007.1
csphereclansphere
2007.2
csphereclansphere
2007.2.1
csphereclansphere
2007.3
csphereclansphere
2007.3.1
csphereclansphere
2007.4
csphereclansphere
2007.4.1
csphereclansphere
2007.4.2
csphereclansphere
2007.4.3
csphereclansphere
2007.4.4
csphereclansphere
2008.0
csphereclansphere
2008.1
csphereclansphere
2008.2
csphereclansphere
2008.2.1
csphereclansphere
2009.0
csphereclansphere
2009.0:rc1
csphereclansphere
2009.0:rc2
csphereclansphere
2009.0:rc3
csphereclansphere
2009.0.1
csphereclansphere
2009.0.2
𝑥
= Vulnerable software versions