7.5
CVSSv2

CVE-2009-3190

Published: 15/09/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote malicious users to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.

Vulnerable Product Search on Vulmon Subscribe to Product

pad-site-scripts pad site scripts 3.6

Exploits

############################################################### #################### Viva IslaM Viva IslaM #################### ## ## Remote SQL Injection Vulnerability ( listphp string ) ## ## PAD Site Scripts v36 ## ## wwwpad-site-scriptscom ## ############################################################### ################################### ...