7.5
CVSSv2

CVE-2009-4933

Published: 12/07/2010 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote malicious users to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

winterwebs ezwebitor

Exploits

-------------------------AllaH AkbaR------------------------------- ezwebitor (Auth Bypass) Remote Sql Injection --------------------------------------------------------------------------- Discovered By: Snakespc ALGERIAN HaCkEr Mail: snakespc@gmailcom Site:wwwsnakespccom/sc/indexphp Chi3arona houa : Serra7 merra7 , koulchi mderra ...