7.5
CVSSv2

CVE-2013-6839

Published: 13/12/2013 Updated: 16/12/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via the orderby parameter to catalog/[id].

Vulnerable Product Search on Vulmon Subscribe to Product

instantsoft instantcms

Exploits

Advisory ID: HTB23185 Product: InstantCMS Vendor: InstantSoft Vulnerable Version(s): 1103 and probably prior Tested Version: 1103 Advisory Publication: November 20, 2013 [without technical details] Vendor Notification: November 20, 2013 Vendor Patch: November 21, 2013 Public Disclosure: December 11, 2013 Vulnerability Type: SQL Injection [ ...
InstantCMS version 1103 suffers from a remote SQL injection vulnerability ...