6.5
CVSSv2

CVE-2008-6282

Published: 25/02/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the city parameter in a users_edit_pub action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ortus.nirn cms ortus 1.12

ortus.nirn cms ortus 1.11

ortus.nirn cms ortus

ortus.nirn cms ortus 1.10.1

Exploits

Author: otmorozok428, forumantichatru Products: CMS Ortus 112, CMS Ortus 113 Vendor: ortusnirnru Download: ortusnirnru/files/ortus1-12zip, ortusnirnru/files/ortus1-13zip Dork (for ALL Versions of CMS Ortus): inurl:indexphp?ortupg= SQL Injection Vulnerability in POST Form: wwwsitecom/indexp ...