58182vdb entry
http://osvdb.org/58182 CVE-2009-3313
FMyClone 2.3 - Multiple SQL Injections
Record summary
CVE-2009-3313 has a selected CVSS score of 6.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the comp parameter to (1) index.php and (2) editComments.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the id parameter in a comment action to edit.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFMyClone 2.3 - Multiple SQL InjectionsExploitDB exploitby learn3r hackerNot analyzed1 file
References
858183vdb entry
http://osvdb.org/58183 58184vdb entry
http://osvdb.org/58184 36778Third-party advisory
http://secunia.com/advisories/36778 9711exploit
http://www.exploit-db.com/exploits/9711 fmyclone-index-sql-injection(53329)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/53329 fmyclone-edit-sql-injection(53330)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/53330 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-3313