6.5
CVSSv2

CVE-2009-1038

Published: 20/03/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 660
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote malicious users to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitrary SQL commands via the (2) user parameter in a modif action to admin/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

yap yap blog 1.1.1

Exploits

####################################################################################################### [+] YAP 111 Blind SQL Injection/SQL Injection [+] Discovered By SirGod [+] wwwmortal-teamorg [+] wwwh4cky0uorg ######################################################################################################## [+] Blind SQL Injection ...
######################################################### # YAP v111 Local File Inclusion Vulnerability # ######################################################### # AUTHOR : Alkindiii # CONTACT : Alkindiii [4T] islamway {D0T} net # HOME : wwwsoqornet # Script : YAP # Version : 111 # Download v11 : wildmarynet ...