10
CVSSv2

CVE-2006-1123

Published: 09/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in D2KBlog 1.0.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via the memName parameter in a cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

d2ksoft d2kblog 1.0.1

d2ksoft d2kblog 1.0.2

d2ksoft d2kblog 1.0.3

d2ksoft d2kblog 1.0

Exploits

#!/usr/bin/perl -w # D2KBLOG SQL injection # Discovered by : Farhad Koosha [ farhadkey [at} kapdair ] # Exploited by : devil_box [ devil_box [at} kapdair ] # member of : Kapdair - Security Science Researchers Institute of Iran (persianhackernet) require LWP::UserAgent; require HTTP::Request; print "\r\n\r\n=-=-=-======================== ...