7.5
CVSSv2

CVE-2009-2439

Published: 13/07/2009 Updated: 13/02/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote malicious users to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party; it is not associated with alibaba.com or the Alibaba Group.

Vulnerable Product Search on Vulmon Subscribe to Product

web development house alibaba clone

Exploits

# [+] Alibaba-clone CMS (SQL/bSQL) Remote SQL Injection # [+] Author : 599eme Man # [+] Contact : Flouf@livefr # [+] Dowload : blogduslerimnet/cms/alibabacom-clone-newhtml # [+] Big Thanks to: Moudi :) >> [+] Exploit : wwwsitecom/path/supplier/view_contact_detailsphp?SellerID=(Blind) or (SQL) wwwsitecom/path ...
----------------------------------------------------------------------- CmS (id) SQL Injection Vulnerability ----------------------------------------------------------------------- Author : spykit Site : devilzc0deorg/ Date : April, 22-2010 Location : Jakarta, Indonesia Time Zone : GMT +7:00 ------------------------------------------------- ...