7.5
CVSSv2

CVE-2003-1504

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote malicious users to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.

Vulnerable Product Search on Vulmon Subscribe to Product

goldscripts goldlink 3.0

Exploits

source: wwwsecurityfocuscom/bid/8847/info GoldLink is prone to SQL injection attacks This is due to insufficient validation of values supplied via cookies As a result, it may be possible to manipulate SQL queries, potentially resulting in information disclosure, bulletin board compromise or other consequences vadmin_login = ' OR Logi ...