6.8
CVSSv2

CVE-2008-5630

Published: 17/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote malicious users to execute arbitrary SQL commands via the umprof_status parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

qualityunit post affiliate pro 3.0

qualityunit post affiliate pro 3.1.4

Exploits

[■] Post Affiliate Pro v3 (indexphp md) <= Blind $ql Injection >©< > AuToR: XaDoS > Contact M&: xados [at] hotmail [dot] it > B§g: Blind $ql inJection > SIte vuln: wwwqualityunitcom/postaffiliatepro/ >©< [■] ExPL0iT: |: wwwexamplecom/postaffiliatepro3/merchants/inde ...