{"containers":{"cna":{"affected":[{"product":"Analytics Stats Counter Statistics Plugin","vendor":"unspecified","versions":[{"status":"affected","version":"1.2.2.5"}]}],"credits":[{"lang":"en","value":"Yorick Koster"}],"descriptions":[{"lang":"en","value":"A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-94","description":"CWE-94 Code Injection","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2022-06-27T18:11:03.000Z","orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB"},"references":[{"tags":["x_refsource_MISC"],"url":"http://seclists.org/fulldisclosure/2017/Feb/74"},{"tags":["x_refsource_MISC"],"url":"https://vuldb.com/?id.97367"}],"title":"Analytics Stats Counter Statistics Plugin code injection","x_generator":"vuldb.com","x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cna@vuldb.com","ID":"CVE-2017-20099","REQUESTER":"cna@vuldb.com","STATE":"PUBLIC","TITLE":"Analytics Stats Counter Statistics Plugin code injection"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Analytics Stats Counter Statistics Plugin","version":{"version_data":[{"version_value":"1.2.2.5"}]}}]},"vendor_name":""}]}},"credit":"Yorick Koster","data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely."}]},"generator":"vuldb.com","impact":{"cvss":{"baseScore":"7.3","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-94 Code Injection"}]}]},"references":{"reference_data":[{"name":"http://seclists.org/fulldisclosure/2017/Feb/74","refsource":"MISC","url":"http://seclists.org/fulldisclosure/2017/Feb/74"},{"name":"https://vuldb.com/?id.97367","refsource":"MISC","url":"https://vuldb.com/?id.97367"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T21:45:25.446Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2017/Feb/74"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://vuldb.com/?id.97367"}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-04-14T16:56:08.838625Z","id":"CVE-2017-20099","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-04-15T14:12:10.791Z"}}]},"cveMetadata":{"assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","assignerShortName":"VulDB","cveId":"CVE-2017-20099","datePublished":"2022-06-27T18:11:03.000Z","dateReserved":"2022-06-25T00:00:00.000Z","dateUpdated":"2025-04-15T14:12:10.791Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}