50314vdb entry
http://osvdb.org/50314 CVE-2008-6274
Family Project 2.x - Authentication Bypass
Record summary
CVE-2008-6274 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the logmbr parameter (aka login field) or (2) the mdpmbr parameter (aka pass or "Mot de passe" field). NOTE: some of these details are obtained from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFamily Project 2.x - Authentication BypassExploitDB exploitby The_5p3ctrumNot analyzed1 file
References
632900Third-party advisory
http://secunia.com/advisories/32900 32501vdb entry
http://www.securityfocus.com/bid/32501 familyproject-index-sql-injection(46929)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/46929 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-6274 7248exploit
https://www.exploit-db.com/exploits/7248