CVE-2010-0614
CVE-2010-0614
SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibly the (2) sub_par or (3) num_quest actions.
Productos afectados
n/a · n/aPoCs públicas encontradas — 2
cve_referencepacketstormsecurity.org/1002-exploits/corelan-10-008-evalmsi.txtno verificadoexploitdbwww.exploit-db.com/exploits/33602no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.org/1002-exploits/corelan-10-008-evalmsi.txthttp://secunia.com/advisories/38478https://exchange.xforce.ibmcloud.com/vulnerabilities/56152http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-008-evalmsi-2-1-03-multiple-vulnerabilities/http://www.osvdb.org/62177http://www.securityfocus.com/archive/1/509370/100/0/threadedhttp://www.securityfocus.com/bid/38116