7.5
CVSSv2

CVE-2009-4745

Published: 26/03/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote malicious users to execute arbitrary SQL commands via the (1) sortField, (2) sortDesc, or (3) pageNumber parameter in a login action.

Vulnerable Product Search on Vulmon Subscribe to Product

dreamlevels dreampoll 3.1

Exploits

During a recent security audit of the DreamPoll 31 software by Dreamlevels, I discovered a number of XSS and SQL Injection vulnerabilities in the application These vulnerabilities could be exploited to make unauthorized changes to a web site or compromise a client accessing a site that utilizes the application Details of the vulnerabilities are ...
source: wwwsecurityfocuscom/bid/36663/info Dream Poll is prone to a cross-site scripting vulnerability and multiple SQL-injection vulnerabilities Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the un ...