Unrated severityNVD Advisory· Published Nov 2, 2011· Updated Apr 29, 2026
CVE-2010-5026
CVE-2010-5026
Description
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information.
Affected products
2cpe:2.3:a:sfiab:science_fair_in_a_box:2.0.6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sfiab:science_fair_in_a_box:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:sfiab:science_fair_in_a_box:2.2.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- packetstormsecurity.org/1006-exploits/fairinabox-sqlxss.txtnvdExploit
- www.exploit-db.com/exploits/13801nvdExploit
- www.securityfocus.com/bid/40743nvdExploit
- secunia.com/advisories/40170nvdVendor Advisory
- www.vupen.com/english/advisories/2010/1428nvdVendor Advisory
- securityreason.com/securityalert/8516nvd
- www.osvdb.org/65420nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/59282nvd
News mentions
0No linked articles in our index yet.