We found results for “”
CVE-2015-5725
Good to know:
Date: February 21, 2018
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary SQL commands via vectors involving the offset variable.
Language: PHP
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-89Top Fix
Upgrade Version
Upgrade to version marcelod/codeistrap - no_fix;iwtb-dev/venda - no_fix;remiheens/smartloader - no_fix;burimaliu/spincmsv2 - v2.0.0;elieldepaula/ci_core - no_fix;nailsapp/common - 0.3.0;wpanel/wpanel4-cms - 3.0.0-beta;acosf/archersys - 2.0.1;acosf/archersys - 2.0.0;webdmg/system-c - v3.0.6;webdmg/system-c - 0.1.1;rogeriopradoj/codeigniter - dev-2.2-stable;rogeriopradoj/codeigniter - dev-upstream-develop;rogeriopradoj/codeigniter - 2.2.4;codeigniter/framework - 2.2.4;webdmg/codeigniter - v3.0.6;webdmg/codeigniter - 0.1.1;hjue/justwriting - no_fix;ellislab/codeigniter - 2.2.4;natanaugusto/codeigniter - no_fix;imagecms/imagecms - v4.9;renanmpimentel/codeigniter_start - no_fix;elieldepaula/wpanelcms - 2.0.0;elieldepaula/wpanelcms - 3.0.0-beta;cloudmanic/cloudmanic-cms - no_fix;iet-ou/open-media-player - no_fix;ardissoebrata/ci-beam - v1.1;foolz/foolfuuka - dev-2-0-stable;dark-prospect-games/facebook-ignited - v1.2.0;jhjjang/sns_login - no_fix;alextselegidis/easyappointments - 1.1.0-beta.1;diyphpdeveloper/cmscanvas - 2.0.x-dev;nwcode4hire/bonfire - v0.6.1;chriskacerguis/codeigniter-restserver - 2.7.2;roulette/roulette - no_fix;vtlfokin/codeigniter - 2.2.4;application/addventure - no_fix;hanischit/codeigniter-restserver - 2.7.2;nails/common - 0.3.0;wargas/database - no_fix;groucho75/ci_html5_auth_crud - no_fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | LOW |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | LOW |
| Authentication (AU): | NONE |
| Confidentiality (C): | PARTIAL |
| Integrity (I): | PARTIAL |
| Availability (A): | PARTIAL |
| Additional information: |
Vulnerabilities
Projects
Contact Us


