7.5
CVSSv2

CVE-2010-2135

Published: 02/06/2010 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) Username and (2) password fields.

Vulnerable Product Search on Vulmon Subscribe to Product

hazelpress hazelpress 0.0.4

Exploits

# HazelPress Lite <= 004 (Auth Bypass) SQL Injection Vulnerability # By cr4wl3r # Download: hazelpressorg/indexphp?hazel=downloads # PoC: [path]/loginphp # Username: ' or '1=1 # password: ' or '1=1 ...