6.8
CVSSv2

CVE-2010-1093

Published: 24/03/2010 Updated: 14/12/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the id parameter in a vp action.

Vulnerable Product Search on Vulmon Subscribe to Product

1024cms 1024 cms 2.1.1

Exploits

# Exploit Title: 1024cms 211 Blind SQL Injection Vulnerability # Date: 07092010 # Author: Stephan Sattler // Solidmediade # Software Website: 1024cmsorg # Software Link: d10xg45o6p6dblcloudfrontnet/projects/f/freecms1024/1024_v2zip or sourceforgenet/projects/cms-cvi/files/v21zip/download # Version: 211 [ Vulnera ...