7.5
CVSSv2

CVE-2011-5230

Published: 25/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) login parameter to sys/login/index or (2) memberLoginName parameter to sys/login/member.

Vulnerable Product Search on Vulmon Subscribe to Product

seotoaster seotoaster 1.8.2

seotoaster seotoaster

seotoaster seotoaster 1.8.3

Exploits

################################################################################# # Advisory: Seotoaster SQL-Injection Admin Login Bypass # Author: Stefan Schurtz # Contact: sschurtz@t-onlinede # Affected Software: Successfully tested on Seotoaster v19 # Vendor URL: wwwseotoastercom/ # Vendor Status: fixed ...