7.5
CVSSv2

CVE-2014-8295

Published: 15/10/2014 Updated: 22/10/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote malicious users to execute arbitrary SQL commands via the jobid parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bacula bacula-web 5.2.10

Exploits

bacula-web 5210 vulnerability Bacula-web is an web base application that provide you a summarized view all of the jobs bacula-director title : Bacula-web 5210 godork : "jobid=" bacula-web vulnerability : + Sql injection example : targetcom/bacula-web/joblogsphp?jobid=99' PoC : @BlackCyber:/media/data/sqlmap$ python sqlmapp ...