7.5
CVSSv2

CVE-2008-5650

Published: 17/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote malicious users to execute arbitrary SQL commands via the pwd parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

alstrasoft webhost directory _nil_

Exploits

[~] AlstraSoft Web Host Directory auth bypass [~] [~] ---------------------------------------------------------- [~] Discovered By: ZoRLu [~] [~] Date: 12112008 [~] [~] Home: wwwz0rlublogspotcom [~] [~] contact: trt-turk@hotmailcom [~] [~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( ( [~] [~] my bug number now: 36 [~] [~] my target bug ...
============================================================================== _ _ _ _ _ _ / \ | | | | / \ | | | | / _ \ | | | | / _ \ | |_| | / ___ \ | |___ | |___ / ___ \ | _ | IN THE NAME OF /_/ ...