7.5
CVSSv2

CVE-2012-4070

Published: 12/08/2012 Updated: 13/08/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote malicious users to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

dir2web dir2web 3.0

Exploits

source: wwwsecurityfocuscom/bid/54845/info Dir2web is prone to multiple security vulnerabilities, including an SQL-Injection vulnerability and an information-disclosure vulnerability Successfully exploiting these issues allows remote attackers to compromise the software, retrieve information, modify data, disclose sensitive information, ...
Dir2web3 version 30 suffers from remote SQL injection and information disclosure vulnerabilities ...