7.5
CVSSv2

CVE-2008-0290

Published: 16/01/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and previous versions allow (1) remote malicious users to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in the gestion_membre.php page to base.php.

Vulnerable Product Search on Vulmon Subscribe to Product

digitalhive digitalhive

Exploits

<!-- Hive v20 RC2 Remote SQL Injection c0ded by j0j0 --> <html> <head> <style type="text/css"> body { margin:3%; font-size:10px; color:#FFFFFF; font-family:Verdana,Arial; background-color:#1a1a1a; text-align: center; } input { background:#303030; color:#FFFFFF; font-family:Verdana ...