6.8
CVSSv2

CVE-2010-2015

Published: 24/05/2010 Updated: 24/05/2010
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote malicious users to execute arbitrary SQL commands via (1) the id parameter in a view_inbox action to cp/cp_messages.php or (2) the id parameter to cp/edit_email.php.

Vulnerable Product Search on Vulmon Subscribe to Product

createch-group lisk cms 4.4

Exploits

Vulnerability ID: HTB22373 Reference: wwwhtbridgech/advisory/sql_injection_vulnerability_in_lisk_cms_1html Product: LiSK CMS Vendor: Createch-group Vulnerable Version: 44 Vendor Notification: 06 May 2010 Vulnerability Type: SQL Injection Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response Risk level: Medium Credit: High-T ...