CVE-2013-6872

SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a projectpdf action.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
o-dyncollabtive
𝑥
≤ 1.1
o-dyncollabtive
0.1
o-dyncollabtive
0.2
o-dyncollabtive
0.2.5
o-dyncollabtive
0.3
o-dyncollabtive
0.3.5
o-dyncollabtive
0.3.6
o-dyncollabtive
0.4
o-dyncollabtive
0.4.5
o-dyncollabtive
0.4.6
o-dyncollabtive
0.4.7
o-dyncollabtive
0.4.8
o-dyncollabtive
0.4.9
o-dyncollabtive
0.4.9.1
o-dyncollabtive
0.5.1
o-dyncollabtive
0.5.5
o-dyncollabtive
0.6
o-dyncollabtive
0.6.1
o-dyncollabtive
0.6.2
o-dyncollabtive
0.6.3
o-dyncollabtive
0.6.4
o-dyncollabtive
0.6.5
o-dyncollabtive
0.7
o-dyncollabtive
0.7.5
o-dyncollabtive
0.7.6
o-dyncollabtive
1.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
collabtive
zesty
dne
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
lucid
dne