7.5
CVSSv2

CVE-2009-2123

Published: 19/06/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote malicious users to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable through login.php; and the (3) id parameter to (b) show_bug.php and (c) show_activity.php. NOTE: it was later reported that vector 3c also affects 1.2.2.

Vulnerable Product Search on Vulmon Subscribe to Product

elvinbts elvinbts 1.2.0

Exploits

################################################################################################################# [+] Elvin BTS 120 Multiple Remote VUlnerabilities [+] Discovered By SirGod [+] wwwmortal-teamorg ################################################################################################################# - Script Homepage : ...