6.8
CVSSv2

CVE-2008-3783

Published: 26/08/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in index.php in Matterdaddy Market 1.1, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the (1) category and (2) type parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

matterdaddy matterdaddy market 1.1

Exploits

Author: ~!Dok_tOR!~ Contact: coder5(at)topmailkz Home Page: wwwantichatru Date found: 250808 Product: Market Version: 11 Download script: wwwmatterdaddycom/4/scripts/market_v1_1zip Vulnerability Class: SQL Injection magic_quotes_gpc = Off localhost/[installdir]/ Exploit: indexphp?category='+union+select+1,2,user(),4,5,6 ...