6.5
CVSSv2

CVE-2021-42666

Published: 05/11/2021 Updated: 30/11/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_question.php, which could let a malicious user extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

engineers online portal project engineers online portal 1.0

Github Repositories

CVE-2021-42666 - SQL Injection vulnerability in the Engineers online portal system.

CVE-2021-42666 CVE-2021-42666 - SQL Injection vulnerability in the Engineers online portal system Technical description: An SQL Injection vulnerability exists in the Engineers Online Portal system An attacker can leverage the vulnerable "id" parameter in the "quiz_questionphp" web page in order to manipulate the sql query performed As a result he can ext

CVE-2021-42666 - SQL Injection vulnerability in the Engineers online portal system.

CVE-2021-42666 CVE-2021-42666 - SQL Injection vulnerability in the Engineers online portal system Technical description: An SQL Injection vulnerability exists in the Engineers Online Portal system An attacker can leverage the vulnerable "id" parameter in the "quiz_questionphp" web page in order to manipulate the sql query performed As a result he can ext