PoC Index

CVE-2009-4698

HIGH 7.5EPSS 1.7%

Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.71% chance of exploitation in the next 30 days, 76th percentile
Published
2010-03-15
Updated
2024-08-07

Proof-of-concept exploits (2)

ExploitDB entries (2)

References

Related