6.8
CVSSv2

CVE-2007-3190

Published: 12/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the (1) user and (2) pass parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

jffnms just for fun network management system 0.8.3

Exploits

source: wwwsecurityfocuscom/bid/24414/info Just For Fun Network Management and Monitoring System (JFFNMS) is prone to multiple remote vulnerabilities, including a cross-site scripting issue, an SQL-injection issue, and multiple information-disclosure issues An attacker can exploit these issues by manipulating the SQL query logic to carr ...