6.5
CVSSv2

CVE-2012-3873

Published: 28/12/2012 Updated: 28/12/2012
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestbook/edit.php, (3) data/file/edit.php, (4) data/htmltext/edit.php, (5) data/publication/edit.php, or (6) data/event/edit.php.

Vulnerable Product Search on Vulmon Subscribe to Product

openconstructor project openconstructor 3.12.0

Exploits

###Title###: Openconstructor CMS 3120 'id' parameter multiple SQL injection vulnerabilities ###Affected Software###: wwwopenconstructororg/ codegooglecom/p/openconstructor/downloads/list esectorsolutionscom/about/whats-new/esector-news/detailed/?id=234 ###Description###: Openconstructor (formerly known as eSector S ...
Openconstructor CMS version 3120 suffers from multiple remote SQL injection vulnerabilities ...