6
CVSSv2

CVE-2009-4595

Published: 12/01/2010 Updated: 13/01/2010
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in PHP Inventory 1.2 allows remote authenticated users to execute arbitrary SQL commands via the sup_id parameter in a suppliers details action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

phpwares php inventory 1.2

Exploits

################################################################# # # PHP Inventory v12 Remote (Auth Bypass) SQL Injection Vulnerabiity # Found By: mr_me # Download: wwwphpwarescom/content/php-inventory # Tested On: Windows Vista # Note: For educational purposes only # ################################################################# Fir ...
PHP Inventory version 131 suffers from a remote SQL injection vulnerability that allows for authentication bypass ...