6.8
CVSSv2

CVE-2009-4925

Published: 12/07/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the username parameter to (1) admin/checkuser.php and (2) checkuser.php.

Vulnerable Product Search on Vulmon Subscribe to Product

creasito creasito e-commerce content manager 1.3.16

Exploits

******* Salvatore "drosophila" Fresta ******* [+] Application: creasito e-commerce content manager [+] Version: 1316 [+] Website: creasitobloghosteriacom [+] Bugs: [A] Authentication Bypass [+] Exploitation: Remote [+] Date: 20 Apr 2009 [+] Discovered by: Salvatore "drosophila" Fresta [+] Author: Salvatore "drosophila" Fresta [+] ...