7.5
CVSSv2

CVE-2008-2197

Published: 14/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote malicious users to execute arbitrary SQL commands via the historymonth parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

miniweb2 blog writer 2.0

Exploits

############################################################################## # Miniweb 20 Admin bypass ############################################################################## # Type: # 'union select 1# # in the username field and press login, you are admin! # # download: wwwminiweb2com/ ########################################### ...
############################################ # Rem0te SQL Injection Vulnerability # # Miniweb 20 [ indexphp ] # ############################################ [<>]Author: HaCkeR-EgY [<>]H^0mE: wwwpal-hackercom , atsdpcom [<>]CONTact: hacker_EGY@hotmailcom =========================================== ...