{ "schema_version": "1.4.0", "id": "GHSA-j49p-v92f-mgvj", "modified": "2022-05-17T04:16:15Z", "published": "2022-05-17T04:16:15Z", "aliases": [ "CVE-2015-1442" ], "details": "SQL injection vulnerability in views/zero_transact_user.php in the administrative backend in ZeroCMS 1.3.3, 1.3.2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a Modify Account action. NOTE: The article_id parameter to zero_view_article.php vector is already covered by CVE-2014-4034.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-1442" }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/130192/ZeroCMS-1.3.3-SQL-Injection.html" }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2015/Feb/4" }, { "type": "WEB", "url": "http://seclists.org/oss-sec/2015/q1/379" }, { "type": "WEB", "url": "http://seclists.org/oss-sec/2015/q1/380" }, { "type": "WEB", "url": "http://sroesemann.blogspot.de/2015/01/report-for-advisory-sroeadv-2015-14.html" }, { "type": "WEB", "url": "http://sroesemann.blogspot.de/2015/01/sroeadv-2015-13.html" }, { "type": "WEB", "url": "http://sroesemann.blogspot.de/2015/02/addition-for-advisory-sroeadv-2015-14.html" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/72398" } ], "database_specific": { "cwe_ids": [ "CWE-89" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2015-02-06T15:59:00Z" } }