7.5
CVSSv2

CVE-2005-4140

Published: 09/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote malicious users to execute arbitrary SQL commands via the username parameter, as used by the user field.

Vulnerable Product Search on Vulmon Subscribe to Product

website baker website baker 2.5.2

website baker website baker 2.6

Exploits

<?php # ---wbaker_260_xplphp 1942 02/12/2005 # # # # Website Baker 260 Login Bypass / remote commands execution # # coded by rgod # # ...