7.5
CVSSv2

CVE-2013-4137

Published: 11/10/2013 Updated: 15/10/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in StatusNet 1.0 prior to 1.0.2 and 1.1.0 allow remote malicious users to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."

Vulnerable Product Search on Vulmon Subscribe to Product

status statusnet 1.0.1

status statusnet 1.0.0

status statusnet 1.1.0