7.5
CVSSv2

CVE-2012-3998

Published: 12/07/2012 Updated: 19/07/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Sticky Notes prior to 0.2.27052012.5 allow remote malicious users to execute arbitrary SQL commands via the (1) paste id in admin/modules/mod_pastes.php or (2) show.php, (3) user id to admin/modules/mod_users.php, (4) project to list.php, or (5) session id to show.php.

Vulnerable Product Search on Vulmon Subscribe to Product

sayakbanerjee sticky notes

sayakbanerjee sticky notes 0.2.27052012.4