CVE-2013-5957

Multiple SQL injection vulnerabilities in CRM/Core/Page/AJAX/Location.php in CiviCRM before 4.2.12, 4.3.x before 4.3.7, and 4.4.x before 4.4.beta4 allow remote attackers to execute arbitrary SQL commands via the _value parameter to (1) ajax/jqState or (2) ajax/jqcounty.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
civicrmcivicrm
4.4:alpha3
civicrmcivicrm
4.4:beta1
civicrmcivicrm
4.4:beta2
civicrmcivicrm
4.4:beta3
civicrmcivicrm
4.4.0:alpha1
civicrmcivicrm
4.4.0:alpha2
civicrmcivicrm
𝑥
≤ 4.2.11
civicrmcivicrm
4.2.0
civicrmcivicrm
4.2.1
civicrmcivicrm
4.2.2
civicrmcivicrm
4.2.4
civicrmcivicrm
4.2.5
civicrmcivicrm
4.2.6
civicrmcivicrm
4.2.7
civicrmcivicrm
4.2.8
civicrmcivicrm
4.2.9
civicrmcivicrm
4.2.10
civicrmcivicrm
4.3.0
civicrmcivicrm
4.3.1
civicrmcivicrm
4.3.2
civicrmcivicrm
4.3.3
civicrmcivicrm
4.3.4
civicrmcivicrm
4.3.5
civicrmcivicrm
4.3.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
civicrm
bullseye
5.33.2+dfsg1-1
fixed
sid
5.68.1+dfsg1-1
fixed