7.5
CVSSv2

CVE-2008-4906

Published: 04/11/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote malicious users to execute arbitrary SQL commands via the l_id parameter. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

w1n78 lyrics 0.4.2

Exploits

e107 Plugin lyrics_menu lyrics_songphp (l_id) Remote Sql inj author: ZoRLu home: z0rlublogspotcom concat: trt-turk@hotmailcom date: 30/10/2008 ( saat 23:36 the_k@m!l'lerdeyim aq :) ) n0te: YALNIZLIK YiTiRDi ANLAMINI YALNIZLIGIMDA : ( ( n0te: aq kpss : ) ) dork: allinurl:"lyrics_menu/lyrics_songphp?l_id=" exploit: localhost/ ...