7.5
CVSSv2

CVE-2009-2603

Published: 27/07/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in index.php in Escon SupportPortal Pro 3.0 allow remote malicious users to execute arbitrary SQL commands via the (1) cat and (2) tid parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

e-supportportal escon supportportal pro 3.0

Exploits

Autor : OzX Sitio : ForoUndersecuritynet Cms : Escon SupportPortal Pro Version : 30 Sitio: wwwe-supportportalcom Tipo Vulnz : Blind Sql Injection Archivo : forumphp Parametro Vulnerable 1 : cat Parametro Vulnerable 2 : tid Source Vulnz (forumphp): 60 - if($_REQUEST["a"]=="rss"){ 61 - $cat=$_REQUEST["cat"]; 62 - $ ...