9.8
CVSSv3

CVE-2015-3934

Published: 21/11/2017 Updated: 12/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote malicious users to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login.

Vulnerable Product Search on Vulmon Subscribe to Product

fiyo fiyo cms 2.0.1.9.1

Exploits

# Exploit Title: Fiyo CMS multiple SQL vulnerability # Date: 2015-06-28 # Exploit Author: cfreer (poc-lab) # Vendor Homepage: wwwfiyoorg/ # Software Link: tcpdiagdlsourceforgenet/project/fiyo-cms/Fiyo%2020/fiyo_cms_202zip # Version: 20_191 # Tested on: Apache/247 (Win32) # CVE : CVE-2015-3934 1、 The vulnerable file ...