PoC Index

CVE-2009-4791

HIGH 7.5EPSS 1.3%

Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to addressbook.php, (2) id parameter to recipes.php, (3) year parameter to register.php, (4) poll_id parameter to home.php, and (5) email parameter to lostpw.php.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.28% chance of exploitation in the next 30 days, 68th percentile
Published
2010-04-22
Updated
2024-08-07

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related