PoC Index

CVE-2009-4798

HIGH 7.5EPSS 1.0%

Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via the (1) kat parameter to side.asp, and the (2) brugerid and (3) password fields to the administration login feature.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.00% chance of exploitation in the next 30 days, 60th percentile
Published
2010-04-22
Updated
2024-08-07

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related