Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50210 | A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/sql.php. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 19 Oct 2024 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Usualtool
Usualtool usualtoolcms |
|
| CPEs | cpe:2.3:a:usualtool:usualtoolcms:9.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Usualtool
Usualtool usualtoolcms |
Tue, 15 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Huangdou
Huangdou utcms |
|
| CPEs | cpe:2.3:a:huangdou:utcms:v9:*:*:*:*:*:*:* | |
| Vendors & Products |
Huangdou
Huangdou utcms |
|
| Metrics |
ssvc
|
Sun, 13 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/sql.php. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | HuangDou UTCMS sql.php RunSql sql injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-10-15T15:00:21.848Z
Reserved: 2024-10-12T16:16:12.159Z
Link: CVE-2024-9918
Updated: 2024-10-15T15:00:14.811Z
Status : Analyzed
Published: 2024-10-13T20:15:03.853
Modified: 2024-10-19T00:47:15.957
Link: CVE-2024-9918
No data.
OpenCVE Enrichment
No data.
EUVD