7.5
CVSSv2

CVE-2010-5039

Published: 02/11/2011 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote malicious users to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

scriptsfeed recipes listing portal 1.0

Exploits

[~] Script: | Recipes Website 10 | [~] Author : MrThieF [~] Contact : LinuxRooT--@hotmailcom <~ [~] DorK : contact_frmphp [~] Software Link : wwwscriptsfeedcom [~] Date : 05-23-2010 [~] Version : 10 [~] CVE : [~] Exploit : UserName : admin ' or ' 1=1 & or & ' or 1='1'# PassworD : xx Example: [site]/[path]/Recip ...