6.8
CVSSv2

CVE-2008-0538

Published: 01/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in phpIP Management 4.3.2 allow remote malicious users to execute arbitrary SQL commands via the (1) password parameter to login.php, the (2) id parameter to display.php, and unspecified other vectors. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

phpip phpip management 4.3.2

Exploits

There exist numerous SQL injection vulnerabilities in phpIP 432, and probably previous versions Most of the data obtained from the request variables ($_GET, $_POST, $_COOKIE, etc) is not sanitized before it is passed to MySQL This may result in un-authorized administrative access to phpIp and read-access to the database, among other things On ...