755
VMScore

CVE-2018-12055

Published: 08/06/2018 Updated: 17/07/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on.

Vulnerable Product Search on Vulmon Subscribe to Product

schools alert management script project schools alert management script -

Exploits

# Exploit Title: Schools Alert Management Script - SQL Injection # Date: 2018-06-07 # Vendor Homepage: wwwphpscriptsmallcom/ # Software Link: wwwphpscriptsmallcom/product/schools-alert-management-system/ # Category: Web Application # Exploit Author: M3@Pandas # Web: githubcom/unh3x/just4cve/issues/2 # Tested on: Linux M ...
Schools Alert Management Script suffers from a remote SQL injection vulnerability ...