20131105 [ISecAuditors Security Advisories] SQL Injection vulnerability in "Project'Or RIA" allow arbitrary access to the database and the file systemmailing list
http://archives.neohapsis.com/archives/bugtraq/2013-11/0020.html CVE-2013-6164
Project'Or RIA 3.4.0 - 'objectDetail.php?objectId' SQL Injection
Record summary
CVE-2013-6164 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrary SQL commands via the objectId parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBProject'Or RIA 3.4.0 - 'objectDetail.php?objectId' SQL InjectionExploitDB exploitby Vicente Aguilera DiazNot analyzed1 file
References
1020131105 [ISecAuditors Security Advisories] SQL Injection vulnerability in "Project'Or RIA" allow arbitrary access to the database and the file systemmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2013-11/0031.html 99367vdb entry
http://osvdb.org/99367 packetstormsecurity.com
http://packetstormsecurity.com/files/123915 projectorria.org
http://projectorria.org/index.php/menu_download_en/menu_history_en 55451Third-party advisory
http://secunia.com/advisories/55451 29517exploit
http://www.exploit-db.com/exploits/29517 63538vdb entry
http://www.securityfocus.com/bid/63538 projeqtor-cve20136164-sql-injection(88584)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/88584 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-6164