7.5
CVSSv2

CVE-2005-1506

Published: 11/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in out.php in CJ Ultra (CJUltra) Plus 1.0.3 and 1.0.4 allows remote malicious users to execute arbitrary SQL commands via the perm parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cj ultra plus 1.0.3

cj ultra plus 1.0.4

Exploits

source: wwwsecurityfocuscom/bid/13533/info CJ Ultra Plus is prone to an SQL injection vulnerability This issue affects the 'outphp' script and could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks /outphp?url=sad&perm=33333333333333333333333333332'%2 ...