6.8
CVSSv2

CVE-2003-1520

Published: 31/12/2003 Updated: 05/09/2008
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote malicious users to execute arbitrary SQL commands via the email parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

fuzzymonkey myclassifieds 2.11

Exploits

source: wwwsecurityfocuscom/bid/8863/info It has been reported that FuzzyMonkey MyClassifieds may be prone to a SQL injection vulnerability that may allow an attacker to disclose user passwords by supplying malicious SQL code to the Email variable This attack may cause the software to write user password to a world readable file, which m ...