7.5
CVSSv2

CVE-2008-6618

Published: 06/04/2009 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in ClassSystem 2.3 allow remote malicious users to execute arbitrary SQL commands via the teacher_id parameter in (1) class/HomepageMain.php and (2) class/HomepageTop.php, and (3) the message_id parameter in class/MessageReply.php.

Vulnerable Product Search on Vulmon Subscribe to Product

netlab classsystem 2.3

Exploits

source: wwwsecurityfocuscom/bid/29372/info ClassSystem is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data These issues include multiple SQL-injection vulnerabilities and an arbitrary-file-upload vulnerability Exploiting these issues could allow an attacker to compromis ...
source: wwwsecurityfocuscom/bid/29372/info ClassSystem is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data These issues include multiple SQL-injection vulnerabilities and an arbitrary-file-upload vulnerability Exploiting these issues could allow an attacker to compromise th ...
source: wwwsecurityfocuscom/bid/29372/info ClassSystem is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data These issues include multiple SQL-injection vulnerabilities and an arbitrary-file-upload vulnerability Exploiting these issues could allow an attacker to compromise ...