6.5
CVSSv2

CVE-2008-6330

Published: 27/02/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in MyTopix 1.3.0 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the send parameter in a notes action.

Vulnerable Product Search on Vulmon Subscribe to Product

jaia interactive mytopix

jaia interactive mytopix 1.2.3

Exploits

<?php /** * * MyTopix <= 130 (notes send) Remote SQL Injection Exploit * Bug discovered & exploited by cOndemned * * Desc : * In order to exploit this vulnerability user have to * be logged on the forum, so I'd decided to write this * exploit x] * * Greetz : * Ex fobidd3n t3am - Sw33t, Kr0licz3k & KraFT, irk4z, * ZaBeaTy, Necro, ...