CVE-2011-5071

Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php, (2) selected[] parameter to tasks.php, (3) sites[] parameter to billable_incidents.php, or (4) search_string parameter to search.php. NOTE: some of these details are obtained from third party information.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
sitrackersupport_incident_tracker
𝑥
≤ 3.63
sitrackersupport_incident_tracker
3.6
sitrackersupport_incident_tracker
3.21
sitrackersupport_incident_tracker
3.22
sitrackersupport_incident_tracker
3.22pl1:pl1
sitrackersupport_incident_tracker
3.23
sitrackersupport_incident_tracker
3.24
sitrackersupport_incident_tracker
3.24:beta-2
sitrackersupport_incident_tracker
3.30
sitrackersupport_incident_tracker
3.30:beta2
sitrackersupport_incident_tracker
3.31
sitrackersupport_incident_tracker
3.32
sitrackersupport_incident_tracker
3.33
sitrackersupport_incident_tracker
3.35
sitrackersupport_incident_tracker
3.35:beta1
sitrackersupport_incident_tracker
3.36
sitrackersupport_incident_tracker
3.40
sitrackersupport_incident_tracker
3.40:beta1
sitrackersupport_incident_tracker
3.41
sitrackersupport_incident_tracker
3.45
sitrackersupport_incident_tracker
3.45:beta1
sitrackersupport_incident_tracker
3.50
sitrackersupport_incident_tracker
3.50:beta1
sitrackersupport_incident_tracker
3.51
sitrackersupport_incident_tracker
3.60
sitrackersupport_incident_tracker
3.61
sitrackersupport_incident_tracker
3.62
sitrackersupport_incident_tracker
3.63:beta1
𝑥
= Vulnerable software versions