6.8
CVSSv2

CVE-2008-4711

Published: 23/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Joovili 3.0 and previous versions, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) view.event.php, (3) view.group.php, (4) view.music.php, (5) view.picture.php, and (6) view.video.php.

Vulnerable Product Search on Vulmon Subscribe to Product

joovili joovili 2.1

joovili joovili

joovili joovili 3.0.6

Exploits

Joovili <= 30 SQL Injection Vulnerability Author: ~!Dok_tOR!~ Date found: 270808 Product: Joovili Version: 30 Price: $155 URL: wwwjoovilicom Download script: rapidsharecom/files/96178834/JooviliPatch301__2ThemesWSTrarhtml Vulnerability Class: SQL Injection Condition: magic_quotes_gpc = Off localhost/[installdir]/ ...