7.5
CVSSv2

CVE-2005-0368

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in CMScore allow remote malicious users to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.

Vulnerable Product Search on Vulmon Subscribe to Product

chipmunk scripts cmscore

Exploits

/*==========================================*/ // GHC -> CMS CORE <- ADVISORY // Product: CMS Core // URL: chipmunk-scriptscom/scripts/cmscorephp // VULNERABILITY CLASS: SQL injection /*==========================================*/ [exploit] Log in with username Administrator'/* from admin/indexphp page # milw0rmcom [2005-02-10] ...