7.5
CVSSv2

CVE-2009-2640

Published: 28/07/2009 Updated: 11/01/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote malicious users to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.

Vulnerable Product Search on Vulmon Subscribe to Product

interlogy profile manager -

Exploits

[~] interlogy Profile Manager Basic (for ByPass) Insecure Cookie Handling Vulnerability [~] [~] ---------------------------------------------------------- [~] Discovered By: ZoRLu [~] [~] Date: 06/06/2009 [~] [~] Home: yildirimordularicom / z0rlublogspotcom [~] [~] msn: trt-turk@hotmailcom [~] [~] N0T: Kpss AnanI [~] ------------------- ...