VU#374092Third-party advisory
http://www.kb.cert.org/vuls/id/374092 CVE-2015-6009
refbase 0.9.6 - Multiple Vulnerabilities
Record summary
CVE-2015-6009 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the sqlQuery parameter to search.php, a different issue than CVE-2015-7382.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBrefbase 0.9.6 - Multiple VulnerabilitiesExploitDB exploitby Mohab AliNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-6009 38292exploit
https://www.exploit-db.com/exploits/38292