7.5
CVSSv2

CVE-2010-4152

Published: 03/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote malicious users to execute arbitrary SQL commands via the cat parameter. NOTE: the i and th vectors are already covered by CVE-2009-0646.

Vulnerable Product Search on Vulmon Subscribe to Product

4site 4site cms

4site 4site cms 2.2

4site 4site cms 2.0

Exploits

source: wwwsecurityfocuscom/bid/44258/info 4Site CMS is prone to an SQL-injection vulnerability An attacker can exploit this issue to carry out unauthorized actions on the underlying database which may compromise the application and may aid in further attacks 4Site CMS 26 is vulnerable; other versions may also be affected ww ...