CVE-2010-0611

Baalsystems Baal Systems < 3.8 - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by cr4wl3r · textwebappsphp
https://www.exploit-db.com/exploits/11346

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56147
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/11346
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38139

Scores

EPSS 0.0037
EPSS Percentile 59.1%

Details

CWE
CWE-89
Status published
Products (3)
baalsystems/baal_systems 3.6
baalsystems/baal_systems 3.7
baalsystems/baal_systems < 3.8
Published Feb 11, 2010
Tracked Since Feb 18, 2026