7.5
CVSSv2

CVE-2009-4791

Published: 22/04/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) prior to 1.8.2 allow remote malicious users to execute arbitrary SQL commands via the (1) letter parameter to addressbook.php, (2) id parameter to recipes.php, (3) year parameter to register.php, (4) poll_id parameter to home.php, and (5) email parameter to lostpw.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ryan haudenschilt family connections 1.6.4

ryan haudenschilt family connections 1.6.3

ryan haudenschilt family connections 1.3

ryan haudenschilt family connections 1.2

ryan haudenschilt family connections 0.9.2

ryan haudenschilt family connections 0.9.1

ryan haudenschilt family connections

ryan haudenschilt family connections 1.8

ryan haudenschilt family connections 1.7.4

ryan haudenschilt family connections 1.6.2

ryan haudenschilt family connections 1.6.1

ryan haudenschilt family connections 1.1.2

ryan haudenschilt family connections 1.1.1

ryan haudenschilt family connections 0.9

ryan haudenschilt family connections 0.8

ryan haudenschilt family connections 1.7.1

ryan haudenschilt family connections 1.7

ryan haudenschilt family connections 1.4

ryan haudenschilt family connections 1.3.1

ryan haudenschilt family connections 0.9.8

ryan haudenschilt family connections 0.9.5

ryan haudenschilt family connections 0.1.2

ryan haudenschilt family connections 0.1.1

ryan haudenschilt family connections 1.7.3

ryan haudenschilt family connections 1.7.2

ryan haudenschilt family connections 1.6

ryan haudenschilt family connections 1.5

ryan haudenschilt family connections 1.1

ryan haudenschilt family connections 1.0

ryan haudenschilt family connections 0.9.9

ryan haudenschilt family connections 0.6

ryan haudenschilt family connections 0.5

Exploits

******* Salvatore "drosophila" Fresta ******* [+] Application: Family Connection [+] Version: <= 182 [+] Website: wwwfamilycmscom [+] Bugs: [A] Blind SQL Injection [+] Exploitation: Remote [+] Date: 1 Apr 2009 [+] Discovered by: Salvatore "drosophila" Fresta [+] Author: Salvatore "drosophila" Fresta [+] Contact: e-mail: drosop ...