Record summary

CVE-2021-47766 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.

Description

Kmaleon 1.1.0.205 contains an authenticated SQL injection vulnerability in the 'tipocomb' parameter of kmaleonW.php that allows attackers to manipulate database queries. Attackers can exploit this vulnerability using boolean-based, error-based, and time-based blind SQL injection techniques to potentially extract or manipulate database information.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 15, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.1.0.205affected

Proofs of concept

1

Catalogued exploits

ExploitDBKmaleon 1.1.0.205 - 'tipocomb' SQL Injection (Authenticated)ExploitDB exploitby Amel BOUZIANE-LEBLONDNot analyzed1 file
ExploitDB

PoC details

References

3