CVE-2013-3527

Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
vanillaforumsvanilla
𝑥
≤ 2.0.18.7
vanillaforumsvanilla
2.0.1
vanillaforumsvanilla
2.0.2
vanillaforumsvanilla
2.0.3
vanillaforumsvanilla
2.0.4
vanillaforumsvanilla
2.0.5
vanillaforumsvanilla
2.0.6
vanillaforumsvanilla
2.0.7
vanillaforumsvanilla
2.0.8
vanillaforumsvanilla
2.0.9
vanillaforumsvanilla
2.0.10
vanillaforumsvanilla
2.0.11
vanillaforumsvanilla
2.0.12
vanillaforumsvanilla
2.0.13
vanillaforumsvanilla
2.0.14
vanillaforumsvanilla
2.0.15
vanillaforumsvanilla
2.0.16
vanillaforumsvanilla
2.0.16.1
vanillaforumsvanilla
2.0.17
vanillaforumsvanilla
2.0.17.1
vanillaforumsvanilla
2.0.17.2
vanillaforumsvanilla
2.0.17.3
vanillaforumsvanilla
2.0.17.4
vanillaforumsvanilla
2.0.17.5
vanillaforumsvanilla
2.0.17.6
vanillaforumsvanilla
2.0.17.7
vanillaforumsvanilla
2.0.17.8
vanillaforumsvanilla
2.0.17.9
vanillaforumsvanilla
2.0.17.10
vanillaforumsvanilla
2.0.18
vanillaforumsvanilla
2.0.18:alpha3
vanillaforumsvanilla
2.0.18:beta1
vanillaforumsvanilla
2.0.18:beta2
vanillaforumsvanilla
2.0.18:beta4
vanillaforumsvanilla
2.0.18:rc1
vanillaforumsvanilla
2.0.18:rc2
vanillaforumsvanilla
2.0.18:rc3
vanillaforumsvanilla
2.0.18.1
vanillaforumsvanilla
2.0.18.3
vanillaforumsvanilla
2.0.18.4
vanillaforumsvanilla
2.0.18.5
vanillaforumsvanilla
2.0.18.6
𝑥
= Vulnerable software versions