7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Boost <= 2.0.3 - Unauthenticated Blind SQL Injection via Multiple Parameters
The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
References
Affected products
- =<2.0.3
Matching in nixpkgs
pkgs.boost
Collection of C++ libraries
pkgs.booster
Fast and secure initramfs generator
pkgs.xgboost
Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library
pkgs.boost177
None
pkgs.boost178
Collection of C++ libraries
pkgs.boost179
Collection of C++ libraries
pkgs.boost180
Collection of C++ libraries
pkgs.boost181
Collection of C++ libraries
pkgs.boost182
Collection of C++ libraries
pkgs.boost183
Collection of C++ libraries
pkgs.boost186
Collection of C++ libraries
pkgs.boost187
Collection of C++ libraries
pkgs.boost188
Collection of C++ libraries
pkgs.boost189
Collection of C++ libraries
pkgs.boost190
Collection of C++ libraries
pkgs.catboost
High-performance library for gradient boosting on decision trees
pkgs.boost-sml
Header only state machine library with no dependencies
pkgs.mev-boost
Ethereum block-building middleware
pkgs.boost-build
None
pkgs.pianobooster
MIDI file player that teaches you how to play the piano
-
nixos-unstable 1.0.0-unstable-2023-01-22
- nixpkgs-unstable 1.0.0-unstable-2023-01-22
- nixos-unstable-small 1.0.0-unstable-2023-01-22
pkgs.nosql-booster
GUI tool for MongoDB Server
pkgs.xgboostWithCuda
Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library
pkgs.emacs-lsp-booster
Emacs LSP performance booster
pkgs.python312Packages.boost
None
pkgs.python313Packages.boost
Collection of C++ libraries
pkgs.python314Packages.boost
Collection of C++ libraries
pkgs.python312Packages.xgboost
None
pkgs.python313Packages.xgboost
Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library
pkgs.python314Packages.xgboost
Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library
pkgs.python313Packages.catboost
High-performance library for gradient boosting on decision trees
pkgs.python314Packages.catboost
High-performance library for gradient boosting on decision trees
pkgs.ibus-engines.typing-booster
Completion input method for faster typing
-
nixos-unstable 2.30.6-with-hunspell
- nixpkgs-unstable 2.30.6-with-hunspell
- nixos-unstable-small 2.30.6-with-hunspell
pkgs.gnomeExtensions.boost-volume
Boosts volume above limits
pkgs.gnomeExtensions.volume-boost
A toggle to Boosts volume above limits | Fork of https://github.com/shaquibimdad/gnome_ext_volume_boost
pkgs.haskellPackages.xgboost-haskell
XGBoost library for Haskell
pkgs.perlPackages.BoostGeometryUtils
Bindings for the Boost Geometry library
pkgs.perl5Packages.BoostGeometryUtils
Bindings for the Boost Geometry library
pkgs.python312Packages.boost-histogram
None
pkgs.python313Packages.boost-histogram
Python bindings for the C++14 Boost::Histogram library
pkgs.python314Packages.boost-histogram
Python bindings for the C++14 Boost::Histogram library
pkgs.perl538Packages.BoostGeometryUtils
None
pkgs.perl540Packages.BoostGeometryUtils
None
pkgs.ibus-engines.typing-booster-unwrapped
Completion input method for faster typing
pkgs.gnomeExtensions.frequency-boost-switch
Add a toggle to enable/disable CPU frequency boost in Gnome Quick Settings menu.
pkgs.pkgsRocm.tests.testers.hasCmakeConfigModules.boost-has-boost_mpi
Test whether boost-1.89.0 exposes cmake-config modules boost_mpi
pkgs.pkgsRocm.tests.testers.hasCmakeConfigModules.boost_mpi-does-not-have-mpi
Test whether boost-1.89.0 exposes cmake-config modules boost_mpi
Package maintainers
-
@ivan-tkatchev Ivan Tkatchev <tkatchev@gmail.com>
-
@prtzl Matej Blagsic <matej.blagsic@protonmail.com>
-
@PlushBeaver Dmitry Kozlyuk <dmitry.kozliuk+nixpkgs@gmail.com>
-
@natsukium Tomoya Otabi <nixpkgs@natsukium.com>
-
@Icy-Thought Icy-Thought <gilganyx@pm.me>
-
@honnip Jung seungwoo <me@honnip.page>
-
@ekimber Edward Kimber <ekimber@protonmail.com>
-
@guillaumematheron Guillaume Matheron <guillaume_nix@matheron.eu>
-
@UlyssesZh Ulysses Zhan <ulysseszhan@gmail.com>
-
@veprbl Dmitry Kalinkin <veprbl@gmail.com>
-
@nviets Nathan Viets <nathan.g.viets@gmail.com>