7.5
CVSSv2

CVE-2008-6798

Published: 07/05/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote malicious users to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).

Vulnerable Product Search on Vulmon Subscribe to Product

preprojects pre real estate listings

Exploits

Pre Real Estate Listings (loginphp) ByPass /File Upload Script:Pre Real Estate Listings HomePage:preprojectcom/ Demo:preprojectcom/ulisting/ Author:BackDoor By Pass Exploit: victimcom/scriptpath/loginphp username:'or' password:'or' Live Demo: preprojectcom/ulisting/loginphp File Upload Exploit: login live demo use ...