← Back

CVE-2017-11174

nvd nist
Published: Jul 12, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses.

Affected (1)

Products: Xoops: Xoops
1 product
Xoops
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.5.8.1

References (2)

Timeline

No history available yet.