6.8
CVSSv2

CVE-2011-5259

Published: 12/02/2013 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM prior to 2.6.11.2 allows remote malicious users to execute arbitrary SQL commands via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

orangehrm orangehrm 2.6.5

orangehrm orangehrm 2.6.4

orangehrm orangehrm 2.6.10

orangehrm orangehrm 2.6.3

orangehrm orangehrm 2.6.2

orangehrm orangehrm 2.6.8

orangehrm orangehrm 2.6.7

orangehrm orangehrm 2.6.6

orangehrm orangehrm 2.6.0.1

orangehrm orangehrm

orangehrm orangehrm 2.6.9

orangehrm orangehrm 2.6.8.1

orangehrm orangehrm 2.6.1

orangehrm orangehrm 2.6.0

Exploits

source: wwwsecurityfocuscom/bid/50857/info OrangeHRM is prone to an SQL-injection and multiple cross-site scripting vulnerabilities Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the und ...