62999vdb entry
http://osvdb.org/62999 CVE-2010-1054
Pars CMS - 'RP' Multiple SQL Injections
Record summary
CVE-2010-1054 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in ParsCMS allow remote attackers to execute arbitrary SQL commands via the RP parameter to (1) fa_default.asp and (2) en_default.asp.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPars CMS - 'RP' Multiple SQL InjectionsExploitDB exploitby IsfahanNot analyzed1 file
References
763000vdb entry
http://osvdb.org/63000 packetstormsecurity.org
http://packetstormsecurity.org/1003-exploits/parscms-sql.txt 39007Third-party advisory
http://secunia.com/advisories/39007 20100315 Pars CMS SQL Injection Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/510066/100/0/threaded 38734vdb entry
http://www.securityfocus.com/bid/38734 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-1054