« Volver al listado

CVE-2008-1895

Estado: ModificadaAlta (7.5)—

Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp, and possibly an unspecified parameter to (3) option_Update.asp in an edit action.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-1895",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-04-18T22:05:00.000",
  "references": [
    {
      "url": "http://bugreport.ir/index.php?/35",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugreport.ir/index.php?/35/exploit",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29827",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/490923/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/28806",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41845",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/5456",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugreport.ir/index.php?/35",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://bugreport.ir/index.php?/35/exploit",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/29827",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/490923/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/28806",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41845",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/5456",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp, and possibly an unspecified parameter to (3) option_Update.asp in an edit action."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de inyección SQL en Carbon Communities 2.4 y anteriores permite a atacantes remotos ejecutar comandos SQL de su elección a través de los parámetros (1) ID a events.asp, (2) UserName a getpassword.asp y posiblemente un parámetro no especificado a (3) option_Update.asp en una acción edit."
    }
  ],
  "lastModified": "2026-06-16T22:52:42.477",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:carboncommunities:carbon_communities:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22855354-0D9B-4594-9F2B-716067F72B85",
              "versionEndIncluding": "2.4"
            },
            {
              "criteria": "cpe:2.3:a:carboncommunities:carbon_communities:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "988F6660-AABE-47C2-A909-E6E91247D440"
            },
            {
              "criteria": "cpe:2.3:a:carboncommunities:carbon_communities:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DE160C1-EDAE-49C5-B2EB-1FB2D7CA634A"
            },
            {
              "criteria": "cpe:2.3:a:carboncommunities:carbon_communities:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D9BEEAC-649E-4DE2-B444-5AF30BAC46DE"
            },
            {
              "criteria": "cpe:2.3:a:carboncommunities:carbon_communities:2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD750FD5-2D87-47D6-A624-77DFD9FCB99A"
            },
            {
              "criteria": "cpe:2.3:a:carboncommunities:carbon_communities:2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61BD9636-04CB-408B-BE62-8161BD171E24"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}