7.5
CVSSv2

CVE-2018-6576

Published: 02/02/2018 Updated: 14/02/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ezcode event manager 1.0

Exploits

# # # # # # Exploit Title: Event Manager PHP Script 10 - SQL Injection # Dork: N/A # Date: 01022018 # Vendor Homepage: ezcodept/ # Software Link: codecanyonnet/item/eventmanager-php-script-admin-panel/21280741 # Version: 10 # Category: Webapps # Tested on: WiN7_x64/KaLiLinuX_x64 # CVE: N/A # # # # # # Exploit Author: Ihsan Senc ...