7.5
CVSSv2

CVE-2018-18399

Published: 20/12/2018 Updated: 09/01/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote malicious user to execute arbitrary SQL commands via the "id" parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jco karma 6.0.0

Exploits

KARMA version 600 suffers from a remote SQL injection vulnerability ...