7.5
CVSSv2

CVE-2010-4780

Published: 07/04/2011 Updated: 22/09/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the check_banlist function in includes/sessions.php in Enano CMS 1.1.7pl1; 1.0.6pl2; and possibly other versions prior to 1.1.8, 1.0.6pl3, and 1.1.7pl2 allows remote malicious users to execute arbitrary SQL commands via the email parameter to index.php. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

enanocms enano cms 1.1.4

enanocms enano cms 1.1.3

enanocms enano cms 0.8.2

enanocms enano cms 0.8.3

enanocms enano cms 1.0.2b1

enanocms enano cms 1.0.3

enanocms enano cms

enanocms enano cms 1.1.6

enanocms enano cms 1.1.5

enanocms enano cms 1.0.6

enanocms enano cms 0.8.1

enanocms enano cms 1.0

enanocms enano cms 1.0.1

enanocms enano cms 1.0.2

enanocms enano cms 1.1.2

enanocms enano cms 1.1.1

enanocms enano cms 0.8.4

enanocms enano cms 0.9.1

enanocms enano cms 1.0.4

enanocms enano cms 1.0.5

enanocms enano cms 1.1.7

enanocms enano cms 0.9.2

enanocms enano cms 0.9.3

Exploits

Vulnerability ID: HTB22709 Reference: wwwhtbridgech/advisory/sql_injection_in_enano_cmshtml Product: Enano CMS Vendor: enanocmsorg ( enanocmsorg/ ) Vulnerable Version: 117pl1 Vendor Notification: 16 November 2010 Vulnerability Type: SQL Injection Status: Fixed by Vendor Risk level: High Credit: High-Tech Bridge SA - Ethical ...