7.5
CVSSv2

CVE-2010-4186

Published: 05/11/2010 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote malicious users to execute arbitrary SQL commands via the password parameter. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

onlinetechtools.com oasys professional 2.10

Exploits

Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoocom] Exploit Title: Onlinetechtools OWOS: Professional Edition? Authentication Bypass Vulnerability Version:210 Price:900$ Vendor url:wwwonlinetechtoolscom Published: 2010-11-02 Thanx to:r0073r (inj3ct0rcom), Sid3^effects, MaYur, MA1201, Sonic, M4n0j,SeeMe, Th3 RDX Greetz to : Inj3ct0r E ...
source: wwwsecurityfocuscom/bid/44608/info Online Work Order Suite is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities i ...