← Back

CVE-2010-1865

nvd nist
Published: May 7, 2010Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in ClanSphere 2009.0.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the IP address to the cs_getip function in generate.php in the Captcha module, or (2) the s_email parameter to the cs_sql_select function in the MySQL database driver (mysql.php).

Affected (25)

Products: Csphere: Clansphere
1 product
Clansphere
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Csphere
Up to 2009.0.3
Version 2007.0
Version 2007.1
Version 2007.2.1
Version 2007.2
Version 2007.3.1
Version 2007.3
Version 2007.4.1
Version 2007.4.2
Version 2007.4.3
Version 2007.4.4
Version 2007.4
Version 2007 rc1
Version 2007 rc2
Version 2007 rc3
Version 2008.0
Version 2008.1
Version 2008.2.1
Version 2008.2
Version 2009.0.1
Version 2009.0.2
Version 2009.0
Version 2009.0 rc1
Version 2009.0 rc2
Version 2009.0 rc3

References (22)

Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
ExploitPatch
Source: cve@mitre.org
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.