7.5
CVSSv2

CVE-2012-3839

Published: 03/07/2012 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in application/core/MY_Model.php in MyClientBase 0.12 allow remote malicious users to execute arbitrary SQL commands via the (1) invoice_number or (2) tags parameter to index.php/invoice_search.

Vulnerable Product Search on Vulmon Subscribe to Product

myclientbase myclientbase 0.12

Exploits

Title: ====== MyClientBase v012 - Multiple Web Vulnerabilities Date: ===== 2012-04-30 References: =========== wwwvulnerability-labcom/get_contentphp?id=511 VL-ID: ===== 511 Introduction: ============= MyClientBase is a simple, intuitive, free and open source web based invoice management system developed with freelancers in mind ...