6.5
CVSSv2

CVE-2012-2236

Published: 20/04/2012 Updated: 20/04/2012
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action.

Vulnerable Product Search on Vulmon Subscribe to Product

ryan walberg php gift registry 1.5.5

Exploits

# Exploit Title: PHP Gift Registry 155 SQL Injection # Date: 02/22/12 # Author: G13 # Software Link: sourceforgenet/projects/phpgiftreg/ # Version: 155 # Category: webapps (php) # ##### Vulnerability ##### The userid parameter in the usersphp file is vulnerable to SQL Injection A user must be signed in to exploit this ##### Exp ...