{ "schema_version": "1.4.0", "id": "GHSA-7c84-xmm4-5pcv", "modified": "2022-05-17T04:15:49Z", "published": "2022-05-17T04:15:49Z", "aliases": [ "CVE-2015-1471" ], "details": "SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to the default URI.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-1471" }, { "type": "WEB", "url": "https://github.com/delta/pragyan/issues/206" }, { "type": "WEB", "url": "https://github.com/delta/pragyan/commit/c93bc100ec93fc78940fbdca9b6b009101858309" }, { "type": "WEB", "url": "http://pastebin.com/ip2gGYuS" }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2015/Feb/18" }, { "type": "WEB", "url": "http://seclists.org/oss-sec/2015/q1/402" }, { "type": "WEB", "url": "http://sroesemann.blogspot.de/2015/01/sroeadv-2015-11.html" }, { "type": "WEB", "url": "http://sroesemann.blogspot.de/2015/02/advisory-for-sroeadv-2015-11.html" } ], "database_specific": { "cwe_ids": [ "CWE-89" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2015-02-12T16:59:00Z" } }