63157vdb entry
http://osvdb.org/63157 CVE-2010-1336
INVOhost - SQL Injection
Record summary
CVE-2010-1336 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) newlanguage parameters to site.php, (3) search parameter to manuals.php, and (4) unspecified vectors to faq.php. NOTE: some of these details are obtained from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBINVOhost - SQL InjectionExploitDB exploitby Andrés GómezNot analyzed1 file
References
863158vdb entry
http://osvdb.org/63158 39095Third-party advisory
http://secunia.com/advisories/39095 11874exploit
http://www.exploit-db.com/exploits/11874 38962vdb entry
http://www.securityfocus.com/bid/38962 invohost-site-sql-injection(57161)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/57161 invohost-manuals-sql-injection(57162)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/57162 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-1336