6.5
CVSSv2

CVE-2008-6641

Published: 07/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via the sid parameter to (1) kanal.asp, (2) google.asp, and (3) hakk.asp in yonet/; and allow remote malicious users to execute arbitrary SQL commands via the (4) username or (5) password fields to yonet/default.asp.

Vulnerable Product Search on Vulmon Subscribe to Product

aspindir shader tv

Exploits

Shader TV (Beta) Multiple Remote SQL Ä°njection Vulnerable Script : wwwaspindircom/indirasp?ID=5441 Script : rapidsharede/files/39341463/ShaderTVziphtml Coded : Asp Lnguae : Acces Discovered By U238 | < Ugurcan Engin > Friends : ka0x - The_BekiR - Marco Almeida - Erhan Bulut - Caborz : Web - Designer Solution ...