7.5
CVSSv2

CVE-2009-4792

Published: 22/04/2010 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote malicious users to execute arbitrary SQL commands via the memid parameter to members.php.

Vulnerable Product Search on Vulmon Subscribe to Product

karl core bandsite cms 1.1.4

Exploits

######################################################################### [+] BandSite CMS 114 (SQL/Upload Shell) Multiple Remote Vulnerabilites [+] Discovered By SirGod [+] wwwmortal-teamorg [+] wwwh4cky0uorg ######################################################################### [+] Remote SQL Injection - The script is full of SQLI bug ...