7.5
CVSSv2

CVE-2010-4856

Published: 05/10/2011 Updated: 14/05/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote malicious users to execute arbitrary SQL commands via the tarih parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

aspindir xweblog 2.2

Exploits

#!/usr/bin/env python #-*- coding:utf-8 -*- ''' # Title : xWeblog v22 (arsivasp tarih) SQL Injection Exploit (py) # Proof : img408imageshackus/img408/7624/sqlmjpg # Script Down : wwwaspdunyasicom/gosterasp?id=19 # Tested : Windows XP Professional sp3 # Author : ZoRLu / inj3ct0rcom/author/57 ...