6.8
CVSSv2

CVE-2010-1109

Published: 25/03/2010 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in index.php in phpMySport 1.4, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the (1) v2 parameter in a member view action, (2) v1 parameter in a news action, (3) v1 parameter in an information action, (4) v2 parameter in a team view action, (5) v2 parameter in a club view action, or (6) v2 parameter in a matches view action.

Vulnerable Product Search on Vulmon Subscribe to Product

djayp phpmysport 1.4

Exploits

##################################################################### # + PhpMySport v 14 Multiple Remote Vulnerabilities (XSS\SQL) + # # ~ Discovered by XaDoS - xados [at] hotmail [dot] it ~ # # ~ Th4nKs AlpHaNiX ~ # ##################################################################### ...