34540Third-party advisory
http://secunia.com/advisories/34540 CVE-2009-4798
Diskos CMS Manager - SQL Injection / File Disclosure / Authentication Bypass
Record summary
CVE-2009-4798 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via the (1) kat parameter to side.asp, and the (2) brugerid and (3) password fields to the administration login feature.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDiskos CMS Manager - SQL Injection / File Disclosure / Authentication BypassExploitDB exploitby AnGeL25dZNot analyzed1 file
References
68307exploit
http://www.exploit-db.com/exploits/8307 34289vdb entry
http://www.securityfocus.com/bid/34289 diskos-side-sql-injection(49509)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/49509 diskos-login-sql-injection(49510)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/49510 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-4798