7.5
CVSSv2

CVE-2012-3471

Published: 12/08/2012 Updated: 13/08/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the edit functions in (1) application/controllers/admin/reports.php and (2) application/controllers/members/reports.php in the Ushahidi Platform prior to 2.5 allow remote malicious users to execute arbitrary SQL commands via an incident id.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ushahidi ushahidi platform 2.3.1

ushahidi ushahidi platform 2.2

ushahidi ushahidi platform 2.0

ushahidi ushahidi platform 1.2

ushahidi ushahidi platform 1.0

ushahidi ushahidi platform

ushahidi ushahidi platform 2.4

ushahidi ushahidi platform 2.3.2

ushahidi ushahidi platform 2.2.1

ushahidi ushahidi platform 2.1