Back to Database
Status published
High
CVE-2010-1994
SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows...
Vulnerability Description
SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the q parameter in conjunction with a /news/search PATH_INFO.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-1994
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/511273/100/0/threaded
- http://secunia.com/advisories/39320
- http://holisticinfosec.org/content/view/141/45/
- http://www.securityfocus.com/bid/40108
- http://osvdb.org/64551
- http://secunia.com/secunia_research/2010-56
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58470
More from tomatocms
View All →CVE-2010-2282
Cross-site request forgery (CSRF) vulnerability in TomatoCMS 2.0.6 allows remote...
Medium
5.1
CVE-2010-2281
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS 2.0.6...
Medium
4.3
CVE-2010-1996
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before...
Low
2.1
CVE-2010-1995
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before...
Low
2.1
CVE-2010-1515
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS 2.0.6...
Low
2.6
Affected Vendor
tomatocms
View all reports →Affected Software
tomatocms
Vulnerable Versions:
0, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.3.1430, 2.0.3.1622
Timeline
Official Publish:
May 20th, 2010
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.