{"api_version":"1","generated_at":"2026-07-23T08:44:41+00:00","cve":"CVE-2010-4845","urls":{"html":"https://cve.report/CVE-2010-4845","api":"https://cve.report/api/cve/CVE-2010-4845.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-4845","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-4845"},"summary":{"title":"CVE-2010-4845","description":"Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-09-27 10:55:05","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.exploit-db.com/exploits/15773","name":"http://www.exploit-db.com/exploits/15773","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Projekt Shop (details.php) Multiple SQL injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/45506","name":"http://www.securityfocus.com/bid/45506","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MH Projekt Shop 'details.php' SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/42711","name":"http://secunia.com/advisories/42711","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MH Products Projekt Shop \"ts\" SQL Injection Vulnerability - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64205","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64205","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-4845","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-4845","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"4845","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mhproducts","cpe5":"projekt_shop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:02:29.545Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"projektshop-details-sql-injection(64205)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64205"},{"name":"42711","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42711"},{"name":"45506","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/45506"},{"name":"15773","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/15773"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-12-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"projektshop-details-sql-injection(64205)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64205"},{"name":"42711","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42711"},{"name":"45506","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/45506"},{"name":"15773","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/15773"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-4845","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"projektshop-details-sql-injection(64205)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64205"},{"name":"42711","refsource":"SECUNIA","url":"http://secunia.com/advisories/42711"},{"name":"45506","refsource":"BID","url":"http://www.securityfocus.com/bid/45506"},{"name":"15773","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/15773"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-4845","datePublished":"2011-09-27T10:00:00.000Z","dateReserved":"2011-09-26T00:00:00.000Z","dateUpdated":"2024-08-07T04:02:29.545Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-09-27 10:55:05","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mhproducts:projekt_shop:*:*:*:*:*:*:*:*","matchCriteriaId":"C167B986-C506-46AC-B8A2-911D08A6D6BE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"4845","Ordinal":"1","Title":"CVE-2010-4845","CVE":"CVE-2010-4845","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"4845","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.","Type":"Description","Title":"CVE-2010-4845"},{"CveYear":"2010","CveId":"4845","Ordinal":"2","NoteData":"2011-09-27","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"4845","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}