7.5
CVSSv2

CVE-2011-5039

Published: 30/12/2011 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote malicious users to execute arbitrary SQL commands via the (1) username and (2) password parameters to login.php, (3) the filter parameter to widget.dokumenti_lista.php, and (4) the fin_nalog_id parameter to nalozi_naslov.php.

Vulnerable Product Search on Vulmon Subscribe to Product

infoproject biznis heroj

Exploits

Infoproject Biznis Heroj (loginphp) Authentication Bypass Vulnerability Vendor: Infoproject DOO Product web page: wwwbiznisherojmk Affected version: Plus, Pro and Extra Summary: Biznis Heroj or Business Hero (Áèçíèñ Õåðî¼) is the first software on the Macedonian market that will help you manage your business processes in you ...