cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2011-0467,https://securityvulnerability.io/vulnerability/CVE-2011-0467,SQL injection in SUSE studio via select parameter,"A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute arbitrary SQL statements via SQL injection. Affected releases are SUSE Studio Onsite: versions prior to 1.0.3-0.18.1, SUSE Studio Onsite 1.1 Appliance: versions prior to 1.1.2-0.25.1.",Suse,"Suse Studio Onsite,Suse Studio Onsite 1.1 Appliance",8.8,HIGH,0.0008699999889358878,false,,false,false,false,,,false,false,,2018-06-07T21:29:00.000Z,0 CVE-2013-3709,https://securityvulnerability.io/vulnerability/CVE-2013-3709,,"WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.",Suse,"Studio Onsite,Suse Lifecycle Management Server,Webyast",,,0.0004600000102072954,false,,false,false,false,,,false,false,,2013-12-23T23:00:00.000Z,0