755
VMScore

CVE-2018-12052

Published: 08/06/2018 Updated: 17/07/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.

Vulnerable Product Search on Vulmon Subscribe to Product

schools alert management script project schools alert management script -

Exploits

# Exploit Title: Schools Alert Management Script - 'get_secphp' SQL Injection # Date: 2018-06-07 # Vendor Homepage: wwwphpscriptsmallcom/ # Software Link: wwwphpscriptsmallcom/product/schools-alert-management-system/ # Category: Web Application # Exploit Author: M3@Pandas # Web: githubcom/unh3x/just4cve/issues/3 # Test ...
Schools Alert Management Script suffers from a remote SQL injection vulnerability ...