7.5
CVSSv2

CVE-2008-4345

Published: 30/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and previous versions allows remote malicious users to execute arbitrary SQL commands via the aid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

webportal webportal cms 0.6.0

webportal webportal cms 0.6_beta

webportal webportal cms

webportal webportal cms 0.7.3

Exploits

#!/usr/bin/perl # --==+============================================================================+==-- # --==+ WebPortal <= 074 Remote SQL Injection Exploit +==-- # --==+============================================================================+==-- # # [*] Discovered By: StAkeR ~ StAkeR@hotmailit # [+] D ...