CVE-2015-10055

CVSS V2 None CVSS V3 None
Description
A vulnerability was found in PictureThisWebServer and classified as critical. This issue affects the function router.post of the file routes/user.js. The manipulation of the argument username/password leads to sql injection. The name of the patch is 68b9dc346e88b494df00d88c7d058e96820e1479. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218399.
Overview
  • CVE ID
  • CVE-2015-10055
  • Assigner
  • cna@vuldb.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-16T18:15:10
  • Last Modified Date
  • 2023-01-24T19:35:21
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:picturethiswebserver_project:picturethiswebserver:*:*:*:*:*:*:*:* 1 OR 2015-02-23
History
Created Old Value New Value Data Type Notes
2023-01-16 18:15:28 Added to TrackCVE
2023-01-16 18:15:29 Weakness Enumeration new
2023-01-17 14:15:20 2023-01-17T13:24:33 CVE Modified Date updated
2023-01-17 14:15:20 Received Awaiting Analysis Vulnerability Status updated
2023-01-17 14:15:24 CVSS V3 information new
2023-01-17 14:15:24 CVSS V2 information new
2023-01-23 15:14:12 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-23 15:14:16 CVSS V3 information new
2023-01-23 15:14:16 CVSS V2 information new
2023-01-24 20:13:54 2023-01-24T19:35:21 CVE Modified Date updated
2023-01-24 20:13:54 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-24 20:13:57 CPE Information updated
2023-01-24 20:13:57 CVSS V3 information new
2023-01-24 20:13:57 CVSS V2 information new