7.5
CVSSv2

CVE-2008-4706

Published: 23/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote malicious users to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php.

Vulnerable Product Search on Vulmon Subscribe to Product

vbulletin vbgooglemap 1.0.3

Exploits

####################################################################### # # Vbgooglemap Hotspot Edition 103 Remote SQL Injection Vulnerability # ####################################################################### # Bug discovered by elusiven # It was priv8 Bug: [Target]/[Path]/vbgooglemaphsephp?do=showdetails&mapid=-1+UNION+SELECT+0, ...