{ "schema_version": "1.4.0", "id": "GHSA-c5fj-m3vw-3xp6", "modified": "2025-04-20T03:50:05Z", "published": "2022-05-14T04:00:37Z", "aliases": [ "CVE-2017-17713" ], "details": "Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, the /register lat parameter, the /register lon parameter, the /register org parameter, the /register query parameter, the /register region parameter, the /register regionName parameter, the /register timezone parameter, the /register vId parameter, the /register zip parameter, or the /tping id parameter.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-17713" }, { "type": "WEB", "url": "https://github.com/boxug/trape/commit/628149159ba25adbfc29a3ae1d4b10c7eb936dd3" }, { "type": "WEB", "url": "https://www.seekurity.com/blog/general/cve-2017-17713-and-cve-2017-17714-multiple-sql-injections-and-xss-vulnerabilities-found-in-the-hackers-tracking-tool-trape-boxug" }, { "type": "WEB", "url": "https://www.youtube.com/watch?v=RWw1UTeZee8" }, { "type": "WEB", "url": "https://www.youtube.com/watch?v=Txp6IwR24jY" }, { "type": "WEB", "url": "https://www.youtube.com/watch?v=efmvL235S-8" } ], "database_specific": { "cwe_ids": [ "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2017-12-16T20:29:00Z" } }