7.5
CVSSv2

CVE-2006-5030

Published: 27/09/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

exv2 content management system

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? print_r(' ------------------------------------------------------------------------------- exV2 <= 2043 "sort" SQL injection / administrative credentials disclosure exploit mail: retrog@aliceit site: retrogodaltervistaorg dork: "Powered by eXV2 Vers" --------------------------------------- ...