7.5
CVSSv2

CVE-2008-2118

Published: 08/05/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in info.php in Project Alumni 1.0.9 allows remote malicious users to execute arbitrary SQL commands via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

project alumni project alumni 1.0.9

Exploits

source: wwwsecurityfocuscom/bid/29019/info Project Alumni is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because the application fails to sufficiently sanitize user-supplied input Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the applicat ...