7.5
CVSSv2

CVE-2009-2591

Published: 24/07/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote malicious users to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

runcms myannonces -

Exploits

================================================================================================ Title : Remote SQL Injection Vulnerability Software : MyAnnonces Module for E-Xoopport 31 Vendor : wwwe-xoopportit/ Date : 17 July 2009 (Indonesia) Author : Vrs-hCk Contact : d00r@telkomnet Blog : c0liblogsp ...