CVE-2010-0611 Information

Description

Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

Reference

http://packetstormsecurity.org/1002-exploits/baalsystems-sql.txt http://www.exploit-db.com/exploits/11346 http://www.securityfocus.com/bid/38139 https://exchange.xforce.ibmcloud.com/vulnerabilities/56147

Share on: