7.5
CVSSv2

CVE-2007-0129

Published: 09/01/2007 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and previous versions allows remote malicious users to execute arbitrary SQL commands via the subcatID parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

locazo locazolist classifieds

Exploits

************************************************************************************* # Title : LocazoList <= v201a beta5 (subcatID) Remote SQL Injection Vulnerability # Author : ajann # Contact : :( # SPage : wwwlocazonet:81 # Dork : "Powered by Locazolist Copyright © 2006" # $$ : $100 **************************** ...