7.5
CVSSv2

CVE-2012-5849

Published: 14/05/2015 Updated: 15/05/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in ClipBucket 2.6 Revision 738 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) uid parameter in an add_friend action to ajax.php; id parameter in a (2) share_object, (3) add_to_fav, (4) rating, or (5) flag_object action to ajax.php; cid parameter in an (6) add_new_item, (7) remove_collection_item, (8) get_item, or (9) load_more_items action to ajax.php; (10) ci_id parameter in a get_item action to ajax.php; user parameter to (11) user_contacts.php or (12) view_channel.php; (13) pid parameter to view_page.php; (14) tid parameter to view_topic.php; or (15) v parameter to watch_video.php.

Vulnerable Product Search on Vulmon Subscribe to Product

clip-bucket clipbucket

Exploits

Advisory ID: HTB23125 Product: ClipBucket Vendor: clip-bucketcom Vulnerable Version(s): 26 Revision 738 and probably prior Tested Version: 26 Revision 738 Vendor Notification: November 7, 2012 Vendor Patch: November 28, 2012 Public Disclosure: December 5, 2012 Vulnerability Type: SQL Injection [CWE-89] CVE Reference: CVE-2012-5849 CVSSv2 Base ...
ClipBucket version 26 revision 738 suffers from a remote SQL injection vulnerability ...

Github Repositories

Access to NVD, download XML files, parse it and stores in sqlite3 database

NVDparser (OBSOLETE DUE TO NVD CHANGING THE PROVIDED XML FILES) Summary This scripts access to NVD (National Vulnerability Database) web page, download XML files from nvdnistgov/downloadcfm, parses them and stores in sqlite3 database The script will not download files already downloaded if the update date is not more recent than the last time it was downloaded The