6.5
CVSSv2

CVE-2014-9457

Published: 02/01/2015 Updated: 05/01/2015
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the id parameter to catalog.php.

Vulnerable Product Search on Vulmon Subscribe to Product

pmb services pmb

Exploits

# Exploit Title: PMB <= 413 Post-Auth SQL Injection Vulnerability # Google Dork: inurl:opac_css # Date: 25-12-2014 # Exploit Author: XD4rker (Ismail Belkacim) # Email: xd4rker[at]gmailcom # Twitter: @xd4rker # Vendor Homepage: wwwsigbnet # Software Link: forgesigbnet/redmine/projects/pmb/files # Affected versions : <= 41 ...