7.5
CVSSv2

CVE-2007-5123

Published: 27/09/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in notas.asp in Novus 1.0 allows remote malicious users to execute arbitrary SQL commands via the nota_id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

solidweb novus 1.0

Exploits

Novus - Sistema de administracion y contenido bug: Sql Inyection official site: novuscommx d0rk: "Powered by Novus" free: no system: asp bug found by ka0x DOM TEAM we: ka0x, an0de, xarnuz, s0cratex ka0x01[at]gmailcom tables: 1- a_notanota_id 2- a_notafe_publicacion 3- a_notaseccion_id 4- a_notasub_sec_id 5- a_notaestatus_id 6- ...