7.5
CVSSv2

CVE-2012-2086

Published: 23/11/2012 Updated: 19/04/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the get_last_conversation_lines function in common/logger.py in Gajim prior to 0.15 allows remote malicious users to execute arbitrary SQL commands via the jig parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

gajim gajim 0.14

gajim gajim 0.13

gajim gajim 0.12.1

gajim gajim 0.12.2

gajim gajim 0.11.2

gajim gajim 0.11.1

gajim gajim 0.8.2

gajim gajim 0.7.1

gajim gajim 0.3

gajim gajim 0.2.1

gajim gajim 0.14.2

gajim gajim 0.14.1

gajim gajim 0.12.5

gajim gajim 0.12

gajim gajim 0.11.4

gajim gajim 0.11

gajim gajim 0.8.1

gajim gajim 0.8

gajim gajim 0.4.1

gajim gajim 0.4

gajim gajim

gajim gajim 0.14.3

gajim gajim 0.13.4

gajim gajim 0.11.3

gajim gajim 0.9

gajim gajim 0.9.1

gajim gajim 0.5.1

gajim gajim 0.5

gajim gajim 0.13.1

gajim gajim 0.13.2

gajim gajim 0.13.3

gajim gajim 0.12.3

gajim gajim 0.12.4

gajim gajim 0.10

gajim gajim 0.10.1

gajim gajim 0.7

gajim gajim 0.6.1

gajim gajim 0.6

gajim gajim 0.2

gajim gajim 0.1

Vendor Advisories

Debian Bug report logs - #668038 gajim code execution and sql injection Package: gajim; Maintainer for gajim is Debian XMPP Maintainers <pkg-xmpp-devel@listsaliothdebianorg>; Source for gajim is src:gajim (PTS, buildd, popcon) Reported by: "Thijs Kinkhorst" <thijs@debianorg> Date: Sun, 8 Apr 2012 13:51:02 UTC S ...
Debian Bug report logs - #668710 gajim: CVE-2012-2093 insecure temporary file creation in LaTeX support Package: gajim; Maintainer for gajim is Debian XMPP Maintainers <pkg-xmpp-devel@listsaliothdebianorg>; Source for gajim is src:gajim (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Sat, 14 ...
Several vulnerabilities have been discovered in Gajim, a feature-rich Jabber client The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2012-1987 Gajim is not properly sanitizing input before passing it to shell commands An attacker can use this flaw to execute arbitrary code on behalf of the victi ...