6.8
CVSSv2

CVE-2009-3494

Published: 30/09/2009 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in index.php in T-HTB Manager 0.5, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via (1) the id parameter in a delete_category action, (2) the name parameter in an update_category action, and other vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

todor lazarov t-htb manager 0.5

Exploits

******** Salvatore "drosophila" Fresta ******** [+] Application: T-HTB Manager [+] Version: 05 [+] Website: sourceforgenet/apps/mediawiki/t-htbmanager/indexphp?title=Main_Page [+] Bugs: [A] Multiple Blind SQL Injection [+] Exploitation: Remote [+] Date: 10 Sep 2009 [+] Discovered by: Salvatore Fresta aka drosophila [+] Author: Sal ...