CVE-2008-6798

Loading...

General

Score:7.5/10.0
Severity:High
Category:SQL Injection
Exploit:Available

Impact Metrics

Confidentiality:Partial
Integrity:Partial
Availability:Partial

Exploitability Metrics

Access Vector:Network
Access Complexity:Low
Authentication:None

Published on 07/05/09 - Updated on 29/09/17

Description

Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).

Category: SQL Injection

CWE-89 (SQL Injection)
The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

Security Notices

US National Vulnerability DatabaseCVE-2008-6798

Exploits

Exploit-DBEDB-7094
SecurityFocusBID-32134

Relative technologies

VendorProduct
preprojectspre_real_estate_listings

Share this vulnerability with:

Twitter Facebook LinkedIn Mail