7.5
CVSSv2

CVE-2008-3297

Published: 25/07/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in SocialEngine (SE) prior to 2.83 allow remote malicious users to execute arbitrary SQL commands via (1) an se_user cookie to include/class_user.php or (2) an se_admin cookie to include/class_admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

social engine social engine 2.0

social engine social engine 1.0

social engine social engine 2.1

social engine social engine 2.4

social engine social engine 1.1

social engine social engine 1.4

social engine social engine 2.5

social engine social engine 2.7

social engine social engine 1.6

social engine social engine 1.7

social engine social engine 1.8

social engine social engine