10
CVSSv2

CVE-2004-1402

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in iWebNegar allows remote malicious users to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page.

Vulnerable Product Search on Vulmon Subscribe to Product

iwebnegar iwebnegar

Exploits

source: wwwsecurityfocuscom/bid/11946/info iWebNegar is reported prone to multiple SQL injection vulnerabilities, these issues exist due to a lack of sufficient boundary checks performed on user-supplied URI parameter data These issues could theoretically be exploited to compromise the software by performing unauthorized actions on the ...