7.5
CVSSv2

CVE-2011-1048

Published: 21/02/2011 Updated: 22/02/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in product.php in MihanTools 1.33 allows remote malicious users to execute arbitrary SQL commands via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mihantools mihantools 1.33

Exploits

# Exploit Title: MihanTools Script SQL Injection Vunerability # Platform: php # Date: 09022011 # Author: WHITE_DEVIL # Software Link: wwwmihantoolsir/ # Version: all version # Tested on: Windows Sp2 # Mail: Mrweb70@yahoocom # Dork: inurl:productphp?id= *Powered by MihanTools* # Exploit: localhost/productph ...