| |
Vulnerability CVE-2008-6142
Published: 2009-02-16 Modified: 2012-02-12
Description: |
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.x versions, allow remote attackers to execute arbitrary SQL commands via (1) the checkuser parameter (aka username field), or (2) the checkpass parameter (aka password field), to admin/index.php. |
See advisories in our WLB2 database: | Topic | Author | Date |
Med. |
| S.W.A.T. | 18.02.2009 |
Type:
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))
CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
7.5/10 |
6.4/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
Partial |
References: |
http://www.milw0rm.com/exploits/7624
https://exchange.xforce.ibmcloud.com/vulnerabilities/47653
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|