7.5
CVSSv2

CVE-2009-4794

Published: 22/04/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote malicious users to execute arbitrary SQL commands via the (1) article_id parameter to view.php and the (2) a parameter in an event action to calendar.php, reachable through index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

community cms community cms 0.5

Exploits

******* Salvatore "drosophila" Fresta ******* [+] Application: Community CMS [+] Version: 05 [+] Website: sourceforgenet/projects/communitycms/ [+] Bugs: [A] Multiple SQL Injection [+] Exploitation: Remote [+] Dork: intext:"Powered by Community CMS" [+] Date: 30 Mar 2009 [+] Discovered by: Salvatore "drosophila" Fresta [+] Author: ...