6
CVSSv2

CVE-2013-6787

Published: 05/12/2013 Updated: 27/12/2013
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and previous versions, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

chamilo chamilo lms 1.8.8.4

chamilo chamilo lms 1.8.8.2

chamilo chamilo lms 1.8.7.1

chamilo chamilo lms 1.8.7

chamilo chamilo lms

chamilo chamilo lms 1.9.4

chamilo chamilo lms 1.9.0

chamilo chamilo lms 1.9.2

chamilo chamilo lms 1.8.8.6

chamilo chamilo lms 1.8.6.2

Exploits

Advisory ID: HTB23182 Product: Chamilo LMS Vendor: Chamilo Association Vulnerable Version(s): 196 and probably prior Tested Version: 196 Advisory Publication: November 6, 2013 [without technical details] Vendor Notification: November 6, 2013 Vendor Patch: November 9, 2013 Public Disclosure: November 27, 2013 Vulnerability Type: SQL Injecti ...
Chamilo LMS version 196 suffers from a remote SQL injection vulnerability ...