6.5
CVSSv2

CVE-2013-2559

Published: 27/03/2014 Updated: 25/08/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Symphony CMS prior to 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated malicious users to execute arbitrary SQL commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

getsymphony symphony 2.0.4

getsymphony symphony 2.0.5

getsymphony symphony 2.0.6

getsymphony symphony 2.0.7

getsymphony symphony 2.0

getsymphony symphony 2.0.3

getsymphony symphony

getsymphony symphony 2.3

getsymphony symphony 2.1.0

getsymphony symphony 2.1.1

Exploits

source: wwwsecurityfocuscom/bid/58843/info Symphony is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlyi ...
Symphony version 231 suffers from a remote SQL injection vulnerability ...