7.5
CVSSv2

CVE-2010-4946

Published: 09/10/2011 Updated: 14/05/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in product_info.php in ALLPC 2.5 allows remote malicious users to execute arbitrary SQL commands via the products_id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

allpcscript allpc 2.5

Exploits

[+]Title Allpc 25 osCommerce SQL-i/XSS Multiple Vulnerabilities [+]Author **RoAd_KiLlEr** [+]Contact RoAd_KiLlEr[at]Khg-Crew[dot]Ws [+]Tested on Win Xp Sp 2/3 --------------------------------------------------------------------------- [~] Founded by **RoAd_KiLlEr** [~] Team: Albanian Hacking Crew [~] Version: 25 ...