CVE-2014-125058 is a critical SQL injection vulnerability affecting the search_first_name function within the search.rb file of the LearnMeSomeCodes project3, specifically impacting the address_book_project and address_book products. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to execute arbitrary SQL commands remotely with low complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While a patch (d3efa17ae9f6b2fc25a6bbcf165cefed17c7035e) is available and recommended, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2014-11-22CPE matchmatch criteria | cpe:2.3:a:address_book_project:address_book:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.