7.5
CVSSv2

CVE-2007-6240

Published: 05/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote malicious users to execute arbitrary SQL commands via the BuildTime parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

snitz communications snitz forums 2000 3.4.06

Exploits

########################## WwWBugReportIR ######################### # # AmnPardaz Security Research & Penetration Testing Group # # Title: A user can gain admin level in snitz 2000 by SQL Injection # vendor: forumsnitzcom/ # Googling: "Powered by Snitz" > 2,440,000 victims # Last bug report in 2007-02-16 with 4692 visitors # ...