7.5
CVSSv2

CVE-2008-3152

Published: 11/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote malicious users to execute arbitrary SQL commands via the idDirectory parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

orbitscripts smartppc pro

orbitscripts smartppc

Exploits

#!/usr/bin/perl -W # SmartPPC Pay Per Click Script Blind SQL Injection Exploit # File affected: directoryphp ($idDirectory) # # Vulnerability: Hamtaro # Exploit: ka0x <ka0x01[at]gmailcom> # # # ka0x@domlabs:~$ /smartppcpl -u "localhost/directoryphp?username=&idDirectory=2" -p Top # [i] Getting default: -T 30 # [i] Getting de ...
+---------------------------------------+ | Blind SQL Injection Vulnerability | | in Pay Per Click Script | | found by Hamtaro aka CorVu5 | |there must be 50 ways to learn to hover| +---------------------------------------+ #gdork: "Pay Per Click Script powered by SmartPPCcom" #vuln: sitecom/directoryphp?username ...