6.5
CVSSv2

CVE-2015-6516

Published: 18/08/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in cygnux.org sysPass 1.0.9 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the search parameter to ajax/ajax_search.php.

Vulnerable Product Search on Vulmon Subscribe to Product

cygnux syspass

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Advisory ID: SYSS-2015-031 Product: sysPass Vendor: cygnuxorg/ Affected Version(s): 109 and below Tested Version(s): 109 Vulnerability Type: SQL Injection (CWE-89) Risk Level: High Solution Status: Fixed Vendor Notification: 2014-07-27 Solution Date: 2014-08-04 Public Disclosure: 2015-0 ...