Record summary

CVE-2008-1968 has a selected CVSS score of 6.0; EIP currently links 2 catalogued exploits.

Description

Multiple SQL injection vulnerabilities in Cezanne 7 allow remote authenticated users to execute arbitrary SQL commands via the FUNID parameter to (1) CFLookup.asp and (2) CznCommon/CznCustomContainer.asp.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBCezanne 7 - 'cflookup.asp?FUNID' SQL InjectionExploitDB exploitby Juan de la Fuente CostaNot analyzed1 file
ExploitDB

PoC details
ExploitDBCezanne 7 - '/CznCommon/CznCustomContainer.asp?FUNID' SQL InjectionExploitDB exploitby Juan de la Fuente CostaNot analyzed1 file
ExploitDB

PoC details

References

6