CVE-2010-4500 describes multiple SQL injection vulnerabilities in contact.php of MRCGIGUY FreeTicket 1.0.0, specifically when magic_quotes_gpc is disabled. Attackers can exploit this by injecting arbitrary SQL commands through the name, email, subject, and message parameters during a sendmess action. This vulnerability carries a CVSS score of 6.8, indicating a medium severity risk with potential for partial compromise of confidentiality, integrity, and availability, requiring medium attack complexity over a network. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:mrcgiguy:freeticket:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.