CVE-2013-2018 — SQL Injection in Boinc
Severity
9.8CRITICALNVD
EPSS
0.6%
top 30.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 20
Latest updateMay 13
Description
Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages6 packages
🔴Vulnerability Details
4GHSA▶
GHSA-xh9c-cqj7-g26j: Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors↗2022-05-05
OSV▶
CVE-2013-2018: Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors↗2020-02-20
💥Exploits & PoCs
8📋Vendor Advisories
7💬Community
4Bugzilla▶
CVE-2018-10843 source-to-image: Builder images with assembler-user LABEL set to root allows attackers to execute arbitrary code↗2018-05-17
Bugzilla▶
CVE-2018-1070 Routing: Malicous Service configuration can bring down routing for an entire shard.↗2018-03-08
Bugzilla▶
CVE-2013-4317 cloudstack: Information disclosure in listProjectAccounts in the CloudStack API↗2018-02-20