6.8
CVSSv2

CVE-2007-5408

Published: 12/10/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in category.php in cpDynaLinks 1.02 allows remote malicious users to execute arbitrary SQL commands via the category parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cplinks cpdynalinks 1.02

Exploits

#!/usr/bin/perl # cpDynaLinks 102 Remote Sql Inyection exploit # download: # wwwcplinkscom/download/cpdynalinks/cpdynalinks_version_1_02_fullzip # bug found by s0cratex # exploit written by ka0x # DOM TEAM 2007 # d0rk: Powered by cpDynaLinks # need magic_quotes_gpc off # contact: <ka0x01[at]gmailcom> <s0cratex[at]nasagov&g ...