7.5
CVSSv2

CVE-2010-4185

Published: 05/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in Energine, possibly 2.3.8 and previous versions, allows remote malicious users to execute arbitrary SQL commands via the NRGNSID cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

energine energine 2.1

energine energine

energine energine 2.2

Exploits

Vulnerability ID: HTB22655 Reference: wwwhtbridgech/advisory/sql_injection_in_energinehtml Product: Energine Vendor: Energine ( energineorg/ ) Vulnerable Version: Vendor Notification: 13 October 2010 Vulnerability Type: SQL Injection Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response Risk level: High Credit: High-Te ...