Record summary

CVE-2009-3968 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php, (2) cate_id parameter to category.php, (3) id parameter to news.php, and (4) productid parameter to itechd.php. NOTE: the sellers_othersitem.php, classifieds.php, and shop.php vectors are already covered by CVE-2008-3238.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBITechBids 8.0 - 'ProductID' Blind SQL InjectionExploitDB exploitby Mr.SQLNot analyzed1 file
ExploitDB

PoC details

References

3