7.5
CVSSv2

CVE-2008-2843

Published: 25/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in doITLive CMS 2.50 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) ID parameter in an USUB action to default.asp and the (2) Licence[SpecialLicenseNumber] (aka LicenceId) cookie to edit/default.asp.

Vulnerable Product Search on Vulmon Subscribe to Product

doitlive cms

Exploits

########################## wwwBugReportir ####################################### # # AmnPardaz Security Research Team # # Title: doITlive CMS <=250 (SQL Injection/XSS) Multiple Vulnerabilities # Vendor: wwwdoitlivecom # Vulnerable Version: 250 and prior versions # Exploit: Available # Impact: High # Fix: N/A # Original Advisory: ww ...