7.5
CVSSv2

CVE-2008-5070

Published: 14/11/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the gud parameter to (1) profiles/index.php and (2) profiles/admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

pro chat rooms pro chat rooms 3.0.3

Exploits

Author: ~!Dok_tOR!~ Date found: 280908 Product: Pro Chat Rooms Version: 303 Price: $55 URL: wwwprochatroomscom Vulnerability Class: SQL Injection Condition: magic_quotes_gpc = Off Exploit 1: localhost/[installdir]/profiles/indexphp?gud=-1'+union+select+1,concat_ws(0x3a,user_name,password,email),3,4,5,6,7,8+from+prochatrooms_users/* ...