7.5
CVSSv2

CVE-2010-5063

Published: 08/10/2012 Updated: 08/10/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote malicious users to execute arbitrary SQL commands via the ratearticleselect parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

vwar virtual war 1.6.1

Exploits

source: wwwsecurityfocuscom/bid/29001/info VWar is prone to multiple remote vulnerabilities, including: - Multiple HTML-injection vulnerabilities - An SQL-injection vulnerability - An unauthorized-access vulnerability - A vulnerability that allows attackers to brute-force authentication credentials An attacker can exploit these issues t ...