CVE-2001-0418 describes a SQL injection vulnerability in the content.pl script of the NCM Content Management System, allowing remote attackers to read arbitrary content from the database by manipulating the 'id' parameter. This medium-severity vulnerability (CVSS 5.0) is easily exploitable over the network with low complexity and no authentication, leading to potential information disclosure. While not listed in CISA's KEV catalog, an ExploitDB entry exists, and the vulnerability has garnered significant community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:ncm:ncm_content_management_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.