Record summary

CVE-2008-6274 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the logmbr parameter (aka login field) or (2) the mdpmbr parameter (aka pass or "Mot de passe" field). NOTE: some of these details are obtained from third party information.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBFamily Project 2.x - Authentication BypassExploitDB exploitby The_5p3ctrumNot analyzed1 file
ExploitDB

PoC details

References

6