CVE-2022-46887

CVSS V2 None CVSS V3 None
Description
Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.
Overview
  • CVE ID
  • CVE-2022-46887
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-19T19:15:10
  • Last Modified Date
  • 2023-01-25T19:51:21
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:nexusphp:nexusphp:*:*:*:*:*:*:*:* 1 OR 1.7.33
History
Created Old Value New Value Data Type Notes
2023-01-19 20:14:28 Added to TrackCVE
2023-01-19 22:15:51 2023-01-19T22:06:06 CVE Modified Date updated
2023-01-19 22:15:51 Received Awaiting Analysis Vulnerability Status updated
2023-01-25 15:14:11 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-25 20:13:53 2023-01-25T19:51:21 CVE Modified Date updated
2023-01-25 20:13:53 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-25 20:13:54 Weakness Enumeration new
2023-01-25 20:13:56 CPE Information updated