6.8
CVSSv2

CVE-2010-4612

Published: 29/12/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in index.php in Hycus CMS 1.0.3, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the (1) user_name and (2) usr_email parameters to user/1/hregister.html, (3) usr_email parameter to user/1/hlogin.html, (4) useremail parameter to user/1/forgotpass.html, and the (5) q parameter to search/1.html. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

hycus hycus cms 1.0.3

Exploits

Vulnerability ID: HTB22737 Reference: wwwhtbridgech/advisory/lfi_in_hycus_cmshtml Product: Hycus CMS Vendor: Hycus Web Development Team ( wwwhycuscom/ ) Vulnerable Version: 103 Vendor Notification: 07 December 2010 Vulnerability Type: LFI Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response Risk level: High Credit: Hi ...