6.8
CVSSv2

CVE-2008-2903

Published: 30/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 up to and including 2.7.1, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the viewnews parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

awbs advanced webhost billing system 2.7

awbs advanced webhost billing system 2.7.1

awbs advanced webhost billing system 2.3.3

awbs advanced webhost billing system 2.5

awbs advanced webhost billing system 2.6.3

Exploits

######################################################################### #################### Viva IslaM Viva IslaM ############################## ## ## Remote SQL Injection Vulnerability ## ## AWBS Versions ( 233 - v250 - v263 - 270 - V271 ) (( newsphp viewnews )) ## ################################################################### ...