7.5
CVSSv2

CVE-2009-0965

Published: 19/03/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in functions/browse.php in Ganesha Digital Library (GDL) 4.0 and 4.2 allows remote malicious users to execute arbitrary SQL commands via the node parameter in a browse action to gdl.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ismail fahmi ganesha digital library 4.0

ismail fahmi ganesha digital library 4.2

Exploits

******************************************************************************************* [ Discovered by g4t3w4y \ jkthackerlink[at]gmailcom ] [ transitory only jakartawebnet/home/GDL-Digital-Library-SQL-Injection-Vulnerabilityhtml :) ] ################################################### # [ GDL v4x ] SQL Injection Vulner ...