CVE-2010-4357

Boka Siteengine - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands via the module parameter.

Exploits (1)

exploitdb WORKING POC
by Beach · textwebappsphp
https://www.exploit-db.com/exploits/15612

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15612
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45056
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42353

Scores

EPSS 0.0011
EPSS Percentile 28.4%

Details

CWE
CWE-89
Status published
Products (1)
boka/siteengine 7.1
Published Dec 01, 2010
Tracked Since Feb 18, 2026