{"api_version":"1","generated_at":"2026-07-24T19:02:13+00:00","cve":"CVE-2010-4362","urls":{"html":"https://cve.report/CVE-2010-4362","api":"https://cve.report/api/cve/CVE-2010-4362.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-4362","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-4362"},"summary":{"title":"CVE-2010-4362","description":"Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-12-01 16:06:13","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.exploit-db.com/exploits/15629","name":"http://www.exploit-db.com/exploits/15629","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"MicroNetSoft RV Dealer Website search.asp, showAlllistings.asp SQL Injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/45089","name":"http://www.securityfocus.com/bid/45089","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MicroNetSoft RV Dealer Websites Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/41319","name":"http://secunia.com/advisories/41319","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MicroNetSoft RV Dealer Website \"vehicletypeID\" SQL Injection Vulnerability - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-4362","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-4362","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"4362","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"micronetsoft","cpe5":"rv_dealer_website","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T03:43:14.741Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"15629","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/15629"},{"name":"45089","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/45089"},{"name":"41319","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/41319"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-11-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-04-09T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"15629","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/15629"},{"name":"45089","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/45089"},{"name":"41319","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/41319"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-4362","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"15629","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/15629"},{"name":"45089","refsource":"BID","url":"http://www.securityfocus.com/bid/45089"},{"name":"41319","refsource":"SECUNIA","url":"http://secunia.com/advisories/41319"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-4362","datePublished":"2010-12-01T16:00:00.000Z","dateReserved":"2010-12-01T00:00:00.000Z","dateUpdated":"2024-08-07T03:43:14.741Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-12-01 16:06:13","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:micronetsoft:rv_dealer_website:*:*:*:*:*:*:*:*","matchCriteriaId":"AB38EED8-2B86-4BD3-9D32-A8E5F0FA7A7A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"4362","Ordinal":"1","Title":"CVE-2010-4362","CVE":"CVE-2010-4362","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"4362","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp.","Type":"Description","Title":"CVE-2010-4362"},{"CveYear":"2010","CveId":"4362","Ordinal":"2","NoteData":"2010-12-01","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"4362","Ordinal":"3","NoteData":"2011-04-09","Type":"Other","Title":"Modified"}]}}}