6.8
CVSSv2

CVE-2008-1513

Published: 25/03/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and previous versions, when the Referers statistics option is enabled, allows remote malicious users to execute arbitrary SQL commands via the HTTP Referer header.

Vulnerable Product Search on Vulmon Subscribe to Product

danneo cms

Exploits

<?php ## Danneo CMS <= 051 Remote Blind SQL Injection Exploit ## Software site: wwwdanneocom/ ## By InATeam (inattackru/) ## Requires "Referers statistics" option turned ON! echo "------------------------------------------------------------\n"; echo "Danneo CMS <= 051 Remote Blind SQL Injection Exploit\n"; echo "(c)od ...