[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-5230Date: (C)2012-10-25   (M)2023-12-22


Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to sys/login/index or (2) memberLoginName parameter to sys/login/member.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
EXPLOIT-DB-18246
SECUNIA-46881
OSVDB-77736
http://www.infoserve.de/system/files/advisories/INFOSERVE-ADV2011-06.txt
seotoaster-loginmodel-sql-injection(71843)

CPE    2
cpe:/a:seotoaster:seotoaster:1.8.3
cpe:/a:seotoaster:seotoaster:1.8.2
CWE    1
CWE-89

© SecPod Technologies